Oracle Product Hub vulnerabilities
10 known vulnerabilities affecting oracle/product_hub.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2021-2289P2HIGHCVSS 8.1≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-04-22
CVE-2021-2289 [HIGH] CVE-2021-2289: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Template, GTI
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Template, GTIN search). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can resul
nvd
CVE-2026-61311P2HIGHCVSS 8.8≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61311 [HIGH] CWE-269 CVE-2026-61311: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Oper
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeo
nvd
CVE-2026-70918P2HIGHCVSS 8.8≥ 12.2.3, ≤ 12.2.152026-08-18
CVE-2026-70918 [HIGH] CWE-306 CVE-2026-70918: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of
nvd
CVE-2026-61312P3HIGHCVSS 8.5≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61312 [HIGH] CWE-284 CVE-2026-61312: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Oper
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. While the vulnerability is in Oracle Product Hub, attacks
nvd
CVE-2026-61310P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61310 [HIGH] CWE-284 CVE-2026-61310: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Oper
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2026-47019P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-47019 [HIGH] CWE-306 CVE-2026-47019: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog)
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2025-53043P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.142025-10-21
CVE-2025-53043 [HIGH] CWE-200 CVE-2025-53043: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog)
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2024-21252P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21252 [HIGH] CWE-862 CVE-2024-21252: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog)
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2026-61274P3MEDIUMCVSS 6.3≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61274 [MEDIUM] CWE-284 CVE-2026-61274: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog)
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2026-61275P3MEDIUMCVSS 6.3≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61275 [MEDIUM] CWE-284 CVE-2026-61275: Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Role Based Se
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Role Based Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in una
nvd