Oracle E-Business Suite vulnerabilities
345 known vulnerabilities affecting oracle/e-business_suite.
Total CVEs
345
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL56HIGH56MEDIUM191LOW42
Vulnerabilities
Page 9 of 18
CVE-2025-50090P4MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.142025-07-15
CVE-2025-50090 [MEDIUM] CWE-352 CVE-2025-50090: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Pe
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interac
nvd
CVE-2026-62486P4MEDIUMCVSS 5.0≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62486 [MEDIUM] CWE-284 CVE-2026-62486: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human in
nvd
CVE-2006-0552P4HIGHCVSS 7.5v11.5.1v11.5.2+8 more2006-02-04
CVE-2006-0552 [HIGH] CVE-2006-0552: Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5,
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.112019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2010-0077P4MEDIUMCVSS 6.4v11.5.10.2v12.0.6+1 more2010-01-13
CVE-2010-0077 [MEDIUM] CVE-2010-0077: Unspecified vulnerability in the CRM Technical Foundation (mobile) component in Oracle E-Business Su
Unspecified vulnerability in the CRM Technical Foundation (mobile) component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2003-1116P4MEDIUMCVSS 5.0v10.7v11.0+8 more2003-12-31
CVE-2003-1116 [MEDIUM] CVE-2003-1116: The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program,
The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.
nvd
CVE-2005-3459P4CRITICALCVSS 10.0v12.0.02005-11-02
CVE-2005-3459 [CRITICAL] CVE-2005-3459: Unspecified vulnerability in Oracle E-Business Suite and Applications 4.5 up to 4.5.1 has unknown im
Unspecified vulnerability in Oracle E-Business Suite and Applications 4.5 up to 4.5.1 has unknown impact and attack vectors, as identified by Oracle Vuln# APPS22 in Oracle Clinical.
nvd
CVE-2006-5346P4HIGHCVSS 7.6v11.5.10.22006-10-18
CVE-2006-5346 [HIGH] CVE-2006-5346: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, as used in Oracle Collaboration Suite 9.0.4
Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, as used in Oracle Collaboration Suite 9.0.4.2 and Oracle E-Business Suite and Applications 11.5.10CU2, has unknown impact and remote attack vectors related to htdigest, aka Vuln# OHS02.
nvd
CVE-2004-1366P4MEDIUMCVSS 4.6v11.5.1v11.5.2+7 more2004-08-04
CVE-2004-1366 [MEDIUM] CWE-255 CVE-2004-1366: Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-read
Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.
nvd
CVE-2010-2388P4MEDIUMCVSS 5.8v11.5.10.22010-10-14
CVE-2010-2388 [MEDIUM] CVE-2010-2388: Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2009-3408P4MEDIUMCVSS 5.1v11.5.102009-10-22
CVE-2009-3408 [MEDIUM] CVE-2009-3408: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2023-21847P4MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.122023-01-18
CVE-2023-21847 [MEDIUM] CVE-2023-21847: Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Download). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks require hu
nvd
CVE-2018-2684P4MEDIUMCVSS 4.9v12.1.3v12.2.3+4 more2018-01-18
CVE-2018-2684 [MEDIUM] CVE-2018-2684: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Regi
Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Registration Process). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks
nvd
CVE-2015-4846P4LOWCVSS 3.6v11.5.10.2v12.0.6+3 more2015-10-21
CVE-2015-4846 [LOW] CVE-2015-4846: Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to SQL Extensions. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims
nvd
CVE-2007-3854P4MEDIUMCVSS 5.5v11.5.8v11.5.9+4 more2007-07-18
CVE-2007-3854 [MEDIUM] CVE-2007-3854: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is
nvd
CVE-2008-7235P4MEDIUMCVSS 4.3v12.0.32009-09-14
CVE-2008-7235 [MEDIUM] CVE-2008-7235: Unspecified vulnerability in the Oracle Forms component in Oracle Application Server 10.1.2.2 and E-
Unspecified vulnerability in the Oracle Forms component in Oracle Application Server 10.1.2.2 and E-Business Suite 12.0.3 allows remote attackers to affect integrity via unknown vectors, aka AS04.
nvd
CVE-2009-3400P4MEDIUMCVSS 5.5v11.5.10.2v12.0.6+1 more2009-10-22
CVE-2009-3400 [MEDIUM] CVE-2009-3400: Unspecified vulnerability in the Oracle Advanced Benefits component in Oracle E-Business Suite 11.5.
Unspecified vulnerability in the Oracle Advanced Benefits component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2013-3756P4MEDIUMCVSS 5.5v12.1.1v12.1.2+1 more2013-07-17
CVE-2013-3756 [MEDIUM] CVE-2013-3756: Unspecified vulnerability in the Oracle Landed Cost Management component in Oracle E-Business Suite
Unspecified vulnerability in the Oracle Landed Cost Management component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Shipment Workbench.
nvd
CVE-2015-1926P4MEDIUMCVSS 5.5v12.2.3v12.2.42015-07-16
CVE-2015-1926 [MEDIUM] CVE-2015-1926: Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.
Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 and 11.1.1.9.0, and the Oracle Applications Framework component in Oracle E-Business Suite 12.2.3 and 12.2.4, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Portal.
nvd
CVE-2015-2652P4MEDIUMCVSS 5.0v10.2v11.5+6 more2015-07-16
CVE-2015-2652 [MEDIUM] CVE-2015-2652: Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12
Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Web Management.
nvd