Oracle E-Business Suite 漏洞列表
共找到 5 个与 Oracle E-Business Suite 相关的漏洞
📅 加载漏洞趋势中...
-
Oracle E-Business Suite /OA_HTML/jtfwrepo.xml 敏感信息泄漏漏洞 无POC
Oracle E-Business Suite存在信息泄露漏洞,攻击者可以利用该漏洞获取大量敏感信息,以供下一步的攻击使用。 -
CVE-2022-21587: Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution POC
Oracle E-Business Suite 12.2.3 through 12.2.11 is susceptible to remote code execution via the Oracle Web Applications Desktop Integrator product, Upload component. An attacker with HTTP network access can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. FOFA: app="Oracle-E-Business-Suite" -
CVE-2017-3528: Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect POC
The Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)) is impacted by open redirect issues in versions 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. These easily exploitable vulnerabilities allow unauthenticated attackers with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. -
CVE-2018-3167: Oracle E-Business Suite - Blind SSRF POC
Oracle E-Business Suite, Application Management Pack component (User Monitoring subcomponent), is susceptible to blind server-side request forgery. An attacker with network access via HTTP can gain read access to a subset of data, connect to internal services like HTTP-enabled databases, or perform post requests towards internal services which are not intended to be exposed. Affected supported versions are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7. -
CVE-2022-21587: Oracle E-Business Suite 12.2.3 -12.2.11 - Remote Code Execution POC
Oracle E-Business Suite 12.2.3 through 12.2.11 is susceptible to remote code execution via the Oracle Web Applications Desktop Integrator product, Upload component. An attacker with HTTP network access can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.