cbcvebase.

Oracle E-Business Suite vulnerabilities

345 known vulnerabilities affecting oracle/e-business_suite.

Total CVEs
345
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL56HIGH56MEDIUM191LOW42

Vulnerabilities

Page 6 of 18
CVE-2007-3866P3HIGHCVSS 7.5v11.5.10.2v12.0.12007-07-18
CVE-2007-3866 [HIGH] CVE-2007-3866: Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 and 12.0.1 allow remote a Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 and 12.0.1 allow remote attackers to have an unknown impact via (a) Oracle Configurator (APPS02), (b) Oracle iExpenses (APPS03), (c) Oracle Application Object Library (APPS09), and (1) APPS12, (2) APPS13, and (3) APPS14 in (d) Oracle Payables.
nvd
CVE-2006-1037P4HIGHCVSS 7.5v11.5.3v11.5.4+8 more2006-03-07
CVE-2006-1037 [HIGH] CVE-2006-1037: SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
nvd
CVE-2026-62490P4MEDIUMCVSS 5.3≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62490 [MEDIUM] CWE-200 CVE-2026-62490: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerabi
nvd
CVE-2006-5367P4CRITICALCVSS 9.0v11.5.7v11.5.8+7 more2006-10-18
CVE-2006-5367 [CRITICAL] CVE-2006-5367: Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.7 up to 11.5.10CU2 have unknown Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.7 up to 11.5.10CU2 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) APPS03 in Oracle Applications Framework, (2) APPS04 in Oracle Applications Technology Stack, and (3) APPS05 in Oracle Balanced Scorecard, (4) APPS09 in Oracle Scripting, and (5) APPS10 in Oracle T
nvd
CVE-2002-1882P4HIGHCVSS 7.5v11.1v11.2+4 more2002-12-31
CVE-2002-1882 [HIGH] CVE-2002-1882: Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 a Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.
nvd
CVE-2016-0514P4MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0514 [MEDIUM] CVE-2016-0514: Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suit Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0515.
nvd
CVE-2016-0515P4MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0515 [MEDIUM] CVE-2016-0515: Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suit Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0514.
nvd
CVE-2016-0510P4MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0510 [MEDIUM] CVE-2016-0510: Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Business Views Catalog.
nvd
CVE-2016-0512P4MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0512 [MEDIUM] CVE-2016-0512: Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10 Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Self Service - Common Modules.
nvd
CVE-2016-0524P4MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0524 [MEDIUM] CVE-2016-0524: Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11 Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Work Provider Administration.
nvd
CVE-2016-0516P4MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0516 [MEDIUM] CVE-2016-0516: Unspecified vulnerability in the Oracle Quality component in Oracle E-Business Suite 11.5.10.2 allow Unspecified vulnerability in the Oracle Quality component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to QA / Order Management Integration.
nvd
CVE-2006-0279P4CRITICALCVSS 10.0v4.32006-01-18
CVE-2006-0279 [CRITICAL] CVE-2006-0279: Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecifie Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component.
nvd
CVE-2006-0278P4CRITICALCVSS 10.0v11.5.92006-01-18
CVE-2006-0278 [CRITICAL] CVE-2006-0278: Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspeci Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS02 in the (a) CRM Technical Foundation component; (2) APPS03 in the (b) iProcurement component; and (3) APPS04, (4) APPS05, and (5) APPS06 in the Oracle Application Object Library component
nvd
CVE-2006-1884P4CRITICALCVSS 10.0v11.0v11.5.1+3 more2006-04-20
CVE-2006-1884 [CRITICAL] CVE-2006-1884: Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business S Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
nvd
CVE-2026-62444P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62444 [MEDIUM] CWE-285 CVE-2026-62444: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human inte
nvd
CVE-2018-2865P4MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2865 [MEDIUM] CVE-2018-2865: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Conso Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Le
nvd
CVE-2018-2873P4MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2873 [MEDIUM] CVE-2018-2873: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Accou Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger.
nvd
CVE-2018-2872P4MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2872 [MEDIUM] CVE-2018-2872: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Accou Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger.
nvd
CVE-2018-2866P4MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2866 [MEDIUM] CVE-2018-2866: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Conso Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Le
nvd
CVE-2007-2126P4CRITICALCVSS 10.0v11.5.10.22007-04-18
CVE-2007-2126 [CRITICAL] CVE-2007-2126: Unspecified vulnerability in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote attack Unspecified vulnerability in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote attack vectors in the (1) Common Applications (APPS01) and (2) iProcurement (APPS02).
nvd
Oracle E-Business Suite vulnerabilities | cvebase