cbcvebase.

Oracle Corporation Application Express vulnerabilities

22 known vulnerabilities affecting oracle_corporation/application_express.

Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM20

Vulnerabilities

Page 1 of 2
CVE-2023-21974CRITICALCVSS 9.0≥ Application Express Team Calendar Plugin: 18.2, ≤ 22.12023-07-18
CVE-2023-21974 [CRITICAL] CVE-2023-21974: Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Team Calen
nvd
CVE-2023-21975CRITICALCVSS 9.0≥ Application Express Customers Plugin: 18.2, ≤ 22.22023-07-18
CVE-2023-21975 [CRITICAL] CVE-2023-21975: Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (com Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Customers Plugin.
nvd
CVE-2023-21983MEDIUMCVSS 5.6≥ Application Express Administration: 18.2, ≤ 22.22023-07-18
CVE-2023-21983 [MEDIUM] CVE-2023-21983: Vulnerability in the Application Express Administration product of Oracle Application Express (compo Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Application Express Administration: 18.2-22.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express Administration. Successful a
nvd
CVE-2021-2460MEDIUMCVSS 5.4≥ unspecified, < 21.1.0.00.042021-07-21
CVE-2021-2460 [MEDIUM] CVE-2021-2460: Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. T Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter. Successful a
nvd
CVE-2021-2117MEDIUMCVSS 5.4≥ unspecified, < 20.22021-01-20
CVE-2021-2117 [MEDIUM] CVE-2021-2117: Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. Vulnerability in the Oracle Application Express Survey Builder component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Survey Builder. Successful attacks
nvd
CVE-2021-2116MEDIUMCVSS 5.4≥ unspecified, < 20.22021-01-20
CVE-2021-2116 [MEDIUM] CVE-2021-2116: Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Ser Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Opportunity Tracker. Successf
nvd
CVE-2020-14763MEDIUMCVSS 5.4≥ unspecified, < 20.22020-10-21
CVE-2020-14763 [MEDIUM] CVE-2020-14763: Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Quick Poll. Successful attacks requir
nvd
CVE-2020-14898MEDIUMCVSS 5.4≥ unspecified, < 20.22020-10-21
CVE-2020-14898 [MEDIUM] CVE-2020-14898: Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. T Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Packaged Apps. Successful attacks
nvd
CVE-2020-14899MEDIUMCVSS 5.4≥ unspecified, < 20.22020-10-21
CVE-2020-14899 [MEDIUM] CVE-2020-14899: Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. T Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter. Successful attacks
nvd
CVE-2020-14900MEDIUMCVSS 5.4≥ unspecified, < 20.22020-10-21
CVE-2020-14900 [MEDIUM] CVE-2020-14900: Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Group Calendar. Successful attack
nvd
CVE-2020-14762MEDIUMCVSS 5.4≥ unspecified, < 20.22020-10-21
CVE-2020-14762 [MEDIUM] CVE-2020-14762: Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported v Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a
nvd
CVE-2020-2972MEDIUMCVSS 5.4v5.1-19.22020-07-15
CVE-2020-2972 [MEDIUM] CWE-79 CVE-2020-2972: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a p
nvd
CVE-2020-2975MEDIUMCVSS 5.4v5.1-19.22020-07-15
CVE-2020-2975 [MEDIUM] CVE-2020-2975: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2977MEDIUMCVSS 4.6v5.1-19.22020-07-15
CVE-2020-2977 [MEDIUM] CVE-2020-2977: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a pe
nvd
CVE-2020-2971MEDIUMCVSS 5.4v5.1-19.22020-07-15
CVE-2020-2971 [MEDIUM] CVE-2020-2971: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2974MEDIUMCVSS 5.4v5.1-19.22020-07-15
CVE-2020-2974 [MEDIUM] CVE-2020-2974: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2513MEDIUMCVSS 5.4v5.1-19.22020-07-15
CVE-2020-2513 [MEDIUM] CWE-79 CVE-2020-2513: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a p
nvd
CVE-2020-2973MEDIUMCVSS 5.4v5.1-19.22020-07-15
CVE-2020-2973 [MEDIUM] CVE-2020-2973: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2976MEDIUMCVSS 5.4v5.1-19.22020-07-15
CVE-2020-2976 [MEDIUM] CVE-2020-2976: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2514MEDIUMCVSS 4.6≥ unspecified, < 19.22020-04-15
CVE-2020-2514 [MEDIUM] CVE-2020-2514: Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported v Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 19.2. Easily exploitable vulnerability allows low privileged attacker having End User Role privilege with network access via HTTPS to compromise Oracle Application Express. Successful attacks require human interaction from a
nvd