Oracle E-Business Suite vulnerabilities
331 known vulnerabilities affecting oracle/e-business_suite.
Total CVEs
331
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL55HIGH50MEDIUM184LOW42
Vulnerabilities
Page 4 of 17
CVE-2018-2684MEDIUMCVSS 4.9v12.1.3v12.2.3+4 more2018-01-18
CVE-2018-2684 [MEDIUM] CVE-2018-2684: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Regi
Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Registration Process). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks
nvd
CVE-2017-3515MEDIUMCVSS 5.4v12.1.3v12.2.3+3 more2017-04-24
CVE-2017-3515 [MEDIUM] CVE-2017-3515: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: User
Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: User Name/Password Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle User Management. Successful atta
nvd
CVE-2016-3520MEDIUMCVSS 4.9v12.1.3v12.2.3+2 more2016-07-21
CVE-2016-3520 [MEDIUM] CVE-2016-3520: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote administrators to affect confidentiality via vectors related to AOL Diagnostic tests.
nvd
CVE-2016-3524MEDIUMCVSS 5.4v12.1.3v12.2.3+2 more2016-07-21
CVE-2016-3524 [MEDIUM] CVE-2016-3524: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Configuration.
nvd
CVE-2016-0511MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0511 [MEDIUM] CVE-2016-0511: Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite
Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0547, CVE-2016-0548, and CVE-2016-0549.
nvd
CVE-2016-0528MEDIUMCVSS 6.4v12.1.1v12.1.2+4 more2016-01-21
CVE-2016-0528 [MEDIUM] CVE-2016-0528: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0529, and CVE-2016-0530.
nvd
CVE-2016-0509MEDIUMCVSS 4.3v11.5.10.22016-01-21
CVE-2016-0509 [MEDIUM] CVE-2016-0509: Unspecified vulnerability in the Oracle Internet Expenses component in Oracle E-Business Suite 11.5.
Unspecified vulnerability in the Oracle Internet Expenses component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to AP Web Utilities.
nvd
CVE-2016-0519MEDIUMCVSS 4.3v11.5.10.22016-01-21
CVE-2016-0519 [MEDIUM] CVE-2016-0519: Unspecified vulnerability in the Oracle iReceivables component in Oracle E-Business Suite 11.5.10.2
Unspecified vulnerability in the Oracle iReceivables component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to AR Web Utilities, a different vulnerability than CVE-2016-0507.
nvd
CVE-2016-0457MEDIUMCVSS 5.0v12.1v12.22016-01-21
CVE-2016-0457 [MEDIUM] CVE-2016-0457: Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Bu
Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote attackers to affect confidentiality via vectors related to REST Framework, a different vulnerability than CVE-2016-0456. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-part
nvd
CVE-2016-0510MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0510 [MEDIUM] CVE-2016-0510: Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite
Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Business Views Catalog.
nvd
CVE-2016-0556MEDIUMCVSS 5.5v11.5.10.2v12.1.1+2 more2016-01-21
CVE-2016-0556 [MEDIUM] CVE-2016-0556: Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Administration, a different vulnerability than CVE-2016-0557.
nvd
CVE-2016-0521MEDIUMCVSS 4.3v11.5.10.22016-01-21
CVE-2016-0521 [MEDIUM] CVE-2016-0521: Unspecified vulnerability in the Oracle iProcurement component in Oracle E-Business Suite 11.5.10.2
Unspecified vulnerability in the Oracle iProcurement component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Redirection.
nvd
CVE-2016-0514MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0514 [MEDIUM] CVE-2016-0514: Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suit
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0515.
nvd
CVE-2016-0512MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0512 [MEDIUM] CVE-2016-0512: Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10
Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Self Service - Common Modules.
nvd
CVE-2016-0459MEDIUMCVSS 4.0v11.5.10.2v12.1.3+3 more2016-01-21
CVE-2016-0459 [MEDIUM] CVE-2016-0459: Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote authenticated users to affect integrity via unknown vectors related to Popup Windows.
nvd
CVE-2016-0526MEDIUMCVSS 5.0v11.5.10.2v12.1.3+3 more2016-01-21
CVE-2016-0526 [MEDIUM] CVE-2016-0526: Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suit
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via unknown vectors related to Wireless Framework.
nvd
CVE-2016-0513MEDIUMCVSS 4.3v11.5.10.22016-01-21
CVE-2016-0513 [MEDIUM] CVE-2016-0513: Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suit
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components.
nvd
CVE-2016-0518MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0518 [MEDIUM] CVE-2016-0518: Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10
Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to General utilities, a different vulnerability than CVE-2016-0517.
nvd
CVE-2016-0507MEDIUMCVSS 4.3v11.5.10.22016-01-21
CVE-2016-0507 [MEDIUM] CVE-2016-0507: Unspecified vulnerability in the Oracle iReceivables component in Oracle E-Business Suite 11.5.10.2
Unspecified vulnerability in the Oracle iReceivables component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to AR Web Utilities, a different vulnerability than CVE-2016-0519.
nvd
CVE-2016-0524MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0524 [MEDIUM] CVE-2016-0524: Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Work Provider Administration.
nvd