Oracle E-Business Suite vulnerabilities
345 known vulnerabilities affecting oracle/e-business_suite.
Total CVEs
345
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL56HIGH56MEDIUM191LOW42
Vulnerabilities
Page 7 of 18
CVE-2010-0859P4MEDIUMCVSS 6.4v11.5.10.22010-04-13
CVE-2010-0859 [MEDIUM] CVE-2010-0859: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 ATG RUP6 allows remote attackers to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2012-3190P4MEDIUMCVSS 6.4v11.5.10.2v12.0.6+3 more2013-01-17
CVE-2012-3190 [MEDIUM] CVE-2012-3190: Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity, related to UWQ Server Issues.
nvd
CVE-2014-6583P4MEDIUMCVSS 6.4v11.5.10.2v12.0.4+5 more2015-01-21
CVE-2014-6583 [MEDIUM] CVE-2014-6583: Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12
Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3. allows remote attackers to affect confidentiality and integrity via unknown vectors related to Audience.
nvd
CVE-2006-1035P4HIGHCVSS 7.5v11.5.3v11.5.4+8 more2006-03-07
CVE-2006-1035 [HIGH] CVE-2006-1035: Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers t
Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to access diagnostics tests via unknown attack vectors.
nvd
CVE-2026-62487P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62487 [MEDIUM] CWE-352 CVE-2026-62487: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human inte
nvd
CVE-2007-5527P4HIGHCVSS 7.5v11.5.10.22007-10-17
CVE-2007-5527 [HIGH] CVE-2007-5527: Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and re
Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and remote attack vectors, related to (1) Application Object Library component (APP01), (2) Contracts Integration (APP02), (3) Applications Manager (APP04), (4) Marketing component (APP05), and (5) Exchange component (APP07).
nvd
CVE-2009-1000P4HIGHCVSS 7.5v11i10cu2v12.0.62009-04-15
CVE-2009-1000 [HIGH] CWE-255 CVE-2009-1000: The Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 uses defa
The Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 uses default passwords for unspecified "FND Applications Users (not DB users)," which has unknown impact and attack vectors.
nvd
CVE-2012-3196P4MEDIUMCVSS 6.4v11.5.10.2v12.0.6+3 more2012-10-17
CVE-2012-3196 [MEDIUM] CVE-2012-3196: Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10
Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and availability, related to PDF generation.
nvd
CVE-2003-0632P4HIGHCVSS 7.5v11.1v11.2+6 more2003-08-27
CVE-2003-0632 [HIGH] CVE-2003-0632: Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Or
Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.5.8 may allow remote attackers to execute arbitrary code via a long URL.
nvd
CVE-2013-0382P4MEDIUMCVSS 6.4v11.5.10.2v12.0.6+3 more2013-01-17
CVE-2013-0382 [MEDIUM] CVE-2013-0382: Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12
Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Campaign Management.
nvd
CVE-2006-1883P4CRITICALCVSS 10.0v11.5.10.12006-04-20
CVE-2006-1883 [CRITICAL] CVE-2006-1883: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite and Applications 11.5.10CU1 has unknown impact and attack vectors, aka Vuln# APPS05.
nvd
CVE-2006-5368P4CRITICALCVSS 10.0v6.2.42006-10-18
CVE-2006-5368 [CRITICAL] CVE-2006-5368: Unspecified vulnerability in Oracle Exchange component in Oracle E-Business Suite 6.2.4 has unknown
Unspecified vulnerability in Oracle Exchange component in Oracle E-Business Suite 6.2.4 has unknown impact and remote attack vectors, aka Vuln# APPS01.
nvd
CVE-2008-0343P4CRITICALCVSS 10.0v11.5.9v11.5.10+5 more2008-01-17
CVE-2008-0343 [CRITICAL] CVE-2008-0343: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8,
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06.
nvd
CVE-2018-2864P4MEDIUMCVSS 5.3v12.1.3v12.2.3+4 more2018-04-19
CVE-2018-2864 [MEDIUM] CVE-2018-2864: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Succe
nvd
CVE-2018-2867P4MEDIUMCVSS 5.3v12.1.3v12.2.3+4 more2018-04-19
CVE-2018-2867 [MEDIUM] CVE-2018-2867: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Succe
nvd
CVE-2018-2934P4MEDIUMCVSS 5.3v12.1.32018-07-18
CVE-2018-2934 [MEDIUM] CWE-665 CVE-2018-2934: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of thi
nvd
CVE-2006-5371P4CRITICALCVSS 9.0v11.5.92006-10-18
CVE-2006-5371 [CRITICAL] CVE-2006-5371: Unspecified vulnerability in Oracle Email Center component in Oracle E-Business Suite 11.5.9 has unk
Unspecified vulnerability in Oracle Email Center component in Oracle E-Business Suite 11.5.9 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS07.
nvd
CVE-2012-0537P4MEDIUMCVSS 6.4v12.1.32012-05-03
CVE-2012-0537 [MEDIUM] CVE-2012-0537: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3 allows remote attackers to affect confidentiality and integrity, related to HTML pages.
nvd
CVE-2013-0381P4MEDIUMCVSS 6.4v11.5.10.2v12.0.6+1 more2013-01-17
CVE-2013-0381 [MEDIUM] CVE-2013-0381: Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suit
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Application Framework.
nvd
CVE-2008-7238P4MEDIUMCVSS 6.0v12.0.32009-09-14
CVE-2008-7238 [MEDIUM] CVE-2008-7238: Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.3 allow (1) local users to affe
Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.3 allow (1) local users to affect confidentiality and integrity via unknown vectors related to the Mobile Application Server component (APP01); (2) remote attackers to affect confidentiality via unknown vectors related to the Oracle Applications Framework (APP03); remote authenticated users
nvd