cbcvebase.

Oracle E-Business Suite vulnerabilities

345 known vulnerabilities affecting oracle/e-business_suite.

Total CVEs
345
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL56HIGH56MEDIUM191LOW42

Vulnerabilities

Page 3 of 18
CVE-2014-4278P3HIGHCVSS 7.5v12.0.6v12.1.3+3 more2014-10-15
CVE-2014-4278 [HIGH] CVE-2014-4278: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Oracle Forms.
nvd
CVE-2004-0385P3CRITICALCVSS 10.0v11i2004-06-01
CVE-2004-0385 [CRITICAL] CVE-2004-0385: Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0 Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, al
nvd
CVE-2004-0543P3CRITICALCVSS 10.0v11.5.1v11.5.2+7 more2004-08-06
CVE-2004-0543 [CRITICAL] CVE-2004-0543: Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5. Multiple SQL injection vulnerabilities in Oracle Applications 11.0 and Oracle E-Business Suite 11.5.1 through 11.5.8 allow remote attackers to execute arbitrary SQL procedures and queries.
nvd
CVE-2019-2498P3HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2498 [HIGH] CVE-2019-2498: Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: P Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: Partner Dash board). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Mana
nvd
CVE-2019-2470P3HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2470 [HIGH] CVE-2019-2470: Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: P Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: Partner Detail). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Manageme
nvd
CVE-2019-2400P3HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2400 [HIGH] CVE-2019-2400: Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registra Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attack
nvd
CVE-2019-2497P3HIGHCVSS 8.2v12.1.3v12.2.3+5 more2019-01-16
CVE-2019-2497 [HIGH] CVE-2019-2497: Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcompon Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Succes
nvd
CVE-2019-2440P3HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2440 [HIGH] CVE-2019-2440: Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Inter Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful att
nvd
CVE-2019-2551P3HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-04-23
CVE-2019-2551 [HIGH] CVE-2019-2551: Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponen Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Ful
nvd
CVE-2004-1371P3CRITICALCVSS 9.0v11.5.1v11.5.2+7 more2004-08-04
CVE-2004-1371 [CRITICAL] CWE-119 CVE-2004-1371: Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code v Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
nvd
CVE-2026-62488P3MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62488 [MEDIUM] CWE-284 CVE-2026-62488: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerabili
nvd
CVE-2006-0289P3CRITICALCVSS 10.0v11.5.102006-01-18
CVE-2006-0289 [CRITICAL] CVE-2006-0289: Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suit Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports Developer component. NOTE: Oracle has not disputed reliable researcher claims that REP05 is the same as CVE-2005
nvd
CVE-2026-62443P3HIGHCVSS 7.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62443 [HIGH] CWE-352 CVE-2026-62443: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human intera
nvd
CVE-2006-3716P3CRITICALCVSS 10.0v11.5.10.22006-07-21
CVE-2006-3716 [CRITICAL] CVE-2006-3716: Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unk Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS01 for Internet Expenses; (2) APPS02, (3) APPS05, (4) APPS06, (5) APPS07, (6) APPS08, (7) APPS09, and (8) APPS10 for Oracle Application Object Library; (9) APPS11, (10) APPS12, and (11) APPS13 for Oracl
nvd
CVE-2006-5354P3CRITICALCVSS 10.0v11.5.10.22006-10-18
CVE-2006-5354 [CRITICAL] CVE-2006-5354: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10 Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0, racle Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# OHS06.
nvd
CVE-2006-5370P3CRITICALCVSS 10.0v11.5.10.22006-10-18
CVE-2006-5370 [CRITICAL] CVE-2006-5370: Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 have unknown impact and r Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) APPS06 for Oracle CRM Gateway for Mobile Devices and (2) APPS08 for Oracle iStore.
nvd
CVE-2023-22093P3MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.122023-10-17
CVE-2023-22093 [MEDIUM] CVE-2023-22093: Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Requisition Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Requisition and Vacancy). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2004-1362P3HIGHCVSS 7.5v11.5.1v11.5.2+7 more2004-08-04
CVE-2004-1362 [HIGH] CVE-2004-1362: The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.
nvd
CVE-2008-0347P3CRITICALCVSS 10.0v11.5.9v11.5.10+5 more2008-01-17
CVE-2008-0347 [CRITICAL] CVE-2008-0347: Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01. NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.
nvd
CVE-2007-2127P3CRITICALCVSS 10.0v12.0.02007-04-18
CVE-2007-2127 [CRITICAL] CVE-2007-2127: Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.0 have unknown impact and remot Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.0 have unknown impact and remote attack vectors via (1) Application Object Library (APPS04), iStore (2) APPS05 and (3) APPS06, (4) iSupport (APPS07), (5) Trade Management (APPS09), (6) Applications Manager (APPS10), and (7) Oracle Report Manager (APPS03).
nvd