Oracle E-Business Suite vulnerabilities
331 known vulnerabilities affecting oracle/e-business_suite.
Total CVEs
331
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL55HIGH50MEDIUM184LOW42
Vulnerabilities
Page 8 of 17
CVE-2013-5890MEDIUMCVSS 5.5v11.5.10.2v12.0.6+4 more2014-01-15
CVE-2013-5890 [MEDIUM] CVE-2013-5890: Unspecified vulnerability in the Oracle Payroll component in Oracle E-Business Suite 11.5.10.2, 12.0
Unspecified vulnerability in the Oracle Payroll component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, 12.1.3, and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Exception Reporting.
nvd
CVE-2014-0398MEDIUMCVSS 5.0v11.5.10.2v12.0.6+2 more2014-01-15
CVE-2014-0398 [MEDIUM] CVE-2014-0398: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Discoverer.
nvd
CVE-2013-5874LOWCVSS 1.7v11.5.10.2v12.0.6+2 more2014-01-15
CVE-2013-5874 [LOW] CVE-2013-5874: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, and 12.2.2 allows local users to affect confidentiality via unknown vectors related to Logging.
nvd
CVE-2013-5792MEDIUMCVSS 5.0v12.12013-10-16
CVE-2013-5792 [MEDIUM] CVE-2013-5792: Unspecified vulnerability in the Techstack component in Oracle E-Business Suite 12.1 allows remote a
Unspecified vulnerability in the Techstack component in Oracle E-Business Suite 12.1 allows remote attackers to affect confidentiality via unknown vectors related to Apache.
nvd
CVE-2013-3756MEDIUMCVSS 5.5v12.1.1v12.1.2+1 more2013-07-17
CVE-2013-3756 [MEDIUM] CVE-2013-3756: Unspecified vulnerability in the Oracle Landed Cost Management component in Oracle E-Business Suite
Unspecified vulnerability in the Oracle Landed Cost Management component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Shipment Workbench.
nvd
CVE-2013-3788MEDIUMCVSS 4.3v11.5.10.2v12.0.6+3 more2013-07-17
CVE-2013-3788 [MEDIUM] CVE-2013-3788: Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 11.5.1
Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Supplier Management.
nvd
CVE-2013-3777MEDIUMCVSS 4.3v11.5.10.2v12.0.6+1 more2013-07-17
CVE-2013-3777 [MEDIUM] CVE-2013-3777: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Signon.
nvd
CVE-2013-3778MEDIUMCVSS 4.3v12.0.6v12.1.32013-07-17
CVE-2013-3778 [MEDIUM] CVE-2013-3778: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Help.
nvd
CVE-2013-3747MEDIUMCVSS 4.0v11.5.10.2v12.0.6+1 more2013-07-17
CVE-2013-3747 [MEDIUM] CVE-2013-3747: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Client System Analyzer.
nvd
CVE-2013-3749LOWCVSS 3.5v11.5.10.2v12.0.6+1 more2013-07-17
CVE-2013-3749 [LOW] CVE-2013-3749: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Logging. NOTE: the previous information is from the July 2013 CPU. Oracle has not commented on claims from a third party that the issue is
nvd
CVE-2013-1524MEDIUMCVSS 4.3v12.0.6v12.1.32013-04-17
CVE-2013-1524 [MEDIUM] CVE-2013-1524: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Attachments.
nvd
CVE-2013-2396MEDIUMCVSS 4.3v12.0.6v12.1.32013-04-17
CVE-2013-2396 [MEDIUM] CVE-2013-2396: Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12
Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via vectors related to HTML OAM client.
nvd
CVE-2013-2388MEDIUMCVSS 5.0v11.5.10.2v12.0.6+1 more2013-04-17
CVE-2013-2388 [MEDIUM] CVE-2013-2388: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect availability via unknown vectors related to Mid Tier File Management.
nvd
CVE-2013-1528MEDIUMCVSS 4.3v11.5.10.2v12.0.6+3 more2013-04-17
CVE-2013-1528 [MEDIUM] CVE-2013-1528: Unspecified vulnerability in the Oracle HRMS component in Oracle E-Business Suite 11.5.10.2, 12.0.6,
Unspecified vulnerability in the Oracle HRMS component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Payroll.
nvd
CVE-2013-1501MEDIUMCVSS 4.3v11.5.10.22013-04-17
CVE-2013-1501 [MEDIUM] CVE-2013-1501: Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2 allows
Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Login.
nvd
CVE-2013-1517LOWCVSS 2.6v11.5.10.2v12.0.6+1 more2013-04-17
CVE-2013-1517 [LOW] CVE-2013-1517: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Diagnostics.
nvd
CVE-2013-0382MEDIUMCVSS 6.4v11.5.10.2v12.0.6+3 more2013-01-17
CVE-2013-0382 [MEDIUM] CVE-2013-0382: Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12
Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Campaign Management.
nvd
CVE-2013-0381MEDIUMCVSS 6.4v11.5.10.2v12.0.6+1 more2013-01-17
CVE-2013-0381 [MEDIUM] CVE-2013-0381: Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suit
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Application Framework.
nvd
CVE-2013-0377MEDIUMCVSS 4.3v11.5.10.2v12.0.6+1 more2013-01-17
CVE-2013-0377 [MEDIUM] CVE-2013-0377: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Client System Analyzer.
nvd
CVE-2012-3190MEDIUMCVSS 6.4v11.5.10.2v12.0.6+3 more2013-01-17
CVE-2012-3190 [MEDIUM] CVE-2012-3190: Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity, related to UWQ Server Issues.
nvd