Oracle Human Resources vulnerabilities

12 known vulnerabilities affecting oracle/human_resources.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH4MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2021-2365HIGHCVSS 8.1≥ 12.1.1, ≤ 12.1.32021-07-21
CVE-2021-2365 [HIGH] CVE-2021-2365: Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: People Ma Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: People Management). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2021-2260HIGHCVSS 8.1v12.1.32021-04-22
CVE-2021-2260 [HIGH] CVE-2021-2260: Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: iRecruitm Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: iRecruitment). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation
nvd
CVE-2020-2956HIGHCVSS 8.1≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.92020-04-15
CVE-2020-2956 [HIGH] CVE-2020-2956: Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability ca
nvd
CVE-2020-2882HIGHCVSS 8.1≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.92020-04-15
CVE-2020-2882 [HIGH] CVE-2020-2882: Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability ca
nvd
CVE-2020-2772MEDIUMCVSS 4.1≥ 12.2.6, ≤ 12.2.92020-04-15
CVE-2020-2772 [MEDIUM] CVE-2020-2772: Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Absence R Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Absence Recording, Maintenance). Supported versions that are affected are 12.2.6-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks require human interaction from
nvd
CVE-2020-2587CRITICALCVSS 9.9≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.92020-01-15
CVE-2020-2587 [CRITICAL] CVE-2020-2587: Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Human Resources. While the vulnerability is in Oracle H
nvd
CVE-2020-2586CRITICALCVSS 9.9≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.92020-01-15
CVE-2020-2586 [CRITICAL] CVE-2020-2586: Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Human Resources. While the vulnerability is in Oracle H
nvd
CVE-2018-2871CRITICALCVSS 9.1v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2871 [CRITICAL] CVE-2018-2871: Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: Gene Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Suc
nvd
CVE-2018-2870CRITICALCVSS 9.1v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2870 [CRITICAL] CVE-2018-2870: Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: Gene Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Suc
nvd
CVE-2018-2869MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2869 [MEDIUM] CVE-2018-2869: Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: Gene Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Succe
nvd
CVE-2018-2868MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2868 [MEDIUM] CVE-2018-2868: Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: Gene Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Succe
nvd
CVE-2016-0537MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0537 [MEDIUM] CVE-2016-0537: Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10 Unspecified vulnerability in the Oracle Human Resources component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Person.
nvd