Showing 6 vulnerabilities on this page for E-Business Suite

Signals CISA KEV Ransomware Nuclei
Oracle vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Oracle E-Business Suite Improper Privilege Management Vulnerability

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C

CVSS9.8v3.1EPSS13.3%PoCs2SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVS

CWE-22CWE-287CWE-444CWE-501CWE-918CWE-93Oct 12, 20251 related artifact
CVSS7.5v3.1EPSS97.8%PoCs4SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Oracle E-Business Suite Unspecified Vulnerability

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CV

CWE-22CWE-284CWE-287Oct 5, 20251 related artifact
CVSS9.8v3.1EPSS99.7%PoCs14SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Oracle E-Business Suite Unspecified Vulnerability

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Avai

CWE-306Oct 18, 20221 related artifact
CVSS9.8v3.1EPSS98.3%PoCs5SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Oracle E-Business Suite Manage Proxies Information Disclosure

Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-regis

May 19, 20221 related artifact
CVSS7.5v3.1EPSS71.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Oracle E-Business Suite Application Mgmt Pack for E-Business Suite Vulnerability

Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote attackers to affect confidentiality via vectors related to REST Framework, a different vulnerability than CVE-2016-0456. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a den

Jan 21, 2016
CVSS5.0v2.0EPSS3.92%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX