cbcvebase.

Oracle E-Business Suite vulnerabilities

345 known vulnerabilities affecting oracle/e-business_suite.

Total CVEs
345
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL56HIGH56MEDIUM191LOW42

Vulnerabilities

Page 8 of 18
CVE-2014-6572P4MEDIUMCVSS 6.4v12.0.4v12.0.5+7 more2015-01-21
CVE-2014-6572 [MEDIUM] CVE-2014-6572: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to List of Values.
nvd
CVE-2014-6581P4MEDIUMCVSS 6.4v11.5.10.2v12.0.4+8 more2015-01-21
CVE-2014-6581 [MEDIUM] CVE-2014-6581: Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 1 Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Extract/Load Programs.
nvd
CVE-2010-0868P4MEDIUMCVSS 5.8v11.5.10.2v12.0.6+1 more2010-04-13
CVE-2010-0868 [MEDIUM] CVE-2010-0868: Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0. Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2006-1881P4CRITICALCVSS 10.0v11.5.92006-04-20
CVE-2006-1881 [CRITICAL] CVE-2006-1881: Unspecified vulnerability in the Financials for Asia/Pacific component in Oracle E-Business Suite an Unspecified vulnerability in the Financials for Asia/Pacific component in Oracle E-Business Suite and Applications 11.5.9 has unknown impact and attack vectors. component, aka Vuln# APPS02.
nvd
CVE-2023-22035P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.122023-07-18
CVE-2023-22035 [MEDIUM] CWE-79 CVE-2023-22035: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module) Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person other th
nvd
CVE-2023-22076P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.122023-10-17
CVE-2023-22076 [MEDIUM] CVE-2023-22076: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Pe Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction fr
nvd
CVE-2025-21489P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.102025-01-21
CVE-2025-21489 [MEDIUM] CWE-352 CVE-2025-21489: Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (componen Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require hum
nvd
CVE-2007-3867P4HIGHCVSS 7.5v11.5.10.22007-07-18
CVE-2007-3867 [HIGH] CVE-2007-3867: Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 have unknown impact and a Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 have unknown impact and attack vectors, related to (1) APPS04, (2) APPS05, and (3) APPS06 in (a) Oracle Application Object Library, (4) APPS07 in Oracle Customer Intelligence, (5) APPS08 in Oracle Payments, (7) APPS10 in Oracle Human Resources, and (8) APPS11 in iRecruitment.
nvd
CVE-2007-3865P4HIGHCVSS 7.5v12.0.12007-07-18
CVE-2007-3865 [HIGH] CVE-2007-3865: Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 1 Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 12.0.1 has unknown impact and remote attack vectors, aka APPS01.
nvd
CVE-2007-0279P4HIGHCVSS 7.5v11.5.10.22007-01-17
CVE-2007-0279 [HIGH] CVE-2007-0279: Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and A Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.
nvd
CVE-2016-0456P4MEDIUMCVSS 5.0v12.1v12.22016-01-21
CVE-2016-0456 [MEDIUM] CVE-2016-0456: Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Bu Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote attackers to affect confidentiality via vectors related to REST Framework, a different vulnerability than CVE-2016-0457. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-part
nvd
CVE-2016-3524P4MEDIUMCVSS 5.4v12.1.3v12.2.3+2 more2016-07-21
CVE-2016-3524 [MEDIUM] CVE-2016-3524: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Configuration.
nvd
CVE-2019-2488P4MEDIUMCVSS 5.3v12.1.3v12.2.3+5 more2019-01-16
CVE-2019-2488 [MEDIUM] CVE-2019-2488: Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcompon Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Session Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Founda
nvd
CVE-2007-5529P4HIGHCVSS 7.5v11.5.10.22007-10-17
CVE-2007-5529 [HIGH] CVE-2007-5529: Unspecified vulnerability in the Oracle Self-Service Web Applications component in client-only insta Unspecified vulnerability in the Oracle Self-Service Web Applications component in client-only installations of Oracle E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka APP08.
nvd
CVE-2006-5373P4CRITICALCVSS 9.0v11.5.10.12006-10-18
CVE-2006-5373 [CRITICAL] CVE-2006-5373: Unspecified vulnerability in Oracle Install Base component in Oracle E-Business Suite 11.5.10CU1 has Unspecified vulnerability in Oracle Install Base component in Oracle E-Business Suite 11.5.10CU1 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS13.
nvd
CVE-2007-2128P4CRITICALCVSS 9.0v11.5.102007-04-18
CVE-2007-2128 [CRITICAL] CVE-2007-2128: Unspecified vulnerability in the Sales Online component for Oracle E-Business Suite 11.5.10 has unkn Unspecified vulnerability in the Sales Online component for Oracle E-Business Suite 11.5.10 has unknown impact and remote authenticated attack vectors, aka APPS08.
nvd
CVE-2004-1365P4MEDIUMCVSS 4.6v11.5.1v11.5.2+7 more2004-08-04
CVE-2004-1365 [MEDIUM] CVE-2004-1365: Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
nvd
CVE-2009-0999P4MEDIUMCVSS 6.8v12.0.62009-04-15
CVE-2009-0999 [MEDIUM] CVE-2009-0999: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-3392P4MEDIUMCVSS 5.4v6.1.0.02009-10-22
CVE-2009-3392 [MEDIUM] CVE-2009-3392: Unspecified vulnerability in the Agile Engineering Data Management (EDM) component in Oracle E-Busin Unspecified vulnerability in the Agile Engineering Data Management (EDM) component in Oracle E-Business Suite 6.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2017-3515P4MEDIUMCVSS 5.4v12.1.3v12.2.3+3 more2017-04-24
CVE-2017-3515 [MEDIUM] CVE-2017-3515: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: User Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: User Name/Password Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle User Management. Successful atta
nvd
Oracle E-Business Suite vulnerabilities | cvebase