« Back to list

Oracle

Oracle Application Object Library: vulnerabilities and CVEs

Oracle Application Object Library has 48 published vulnerabilities, 14 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs48
Last 12 months14
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-83184High (7.4)0.32%—Sep 15, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows…
CVE-2026-83178High (8)0.36%—Sep 15, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high…
CVE-2026-83163High (8.8)0.42%—Sep 15, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability…
CVE-2026-83162High (7.4)0.32%—Sep 15, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows…
CVE-2026-83167High (7.5)0.42%—Sep 15, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows…
CVE-2026-61116High (7.5)0.44%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows…
CVE-2026-61114High (7.5)0.33%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows…
CVE-2026-61113High (7.4)0.34%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows…
CVE-2026-61111Medium (6.5)0.15%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low…
CVE-2026-60777Medium (6.3)0.26%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low…
CVE-2026-60776Medium (6.7)0.18%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows…
CVE-2026-60773Critical (9.6)0.36%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low…
CVE-2026-60770High (7.5)0.33%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low…
CVE-2026-60154Medium (5.4)0.23%—Jul 21, 2026
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low…
CVE-2025-30732Medium (6.1)0.25%—Apr 15, 2025
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows…
CVE-2025-30730High (7.5)0.45%—Apr 15, 2025
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows…
CVE-2025-30726Medium (5.3)0.32%—Apr 15, 2025
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows…
CVE-2024-21128Medium (5.4)0.31%—Jul 16, 2024
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: APIs). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows low…
CVE-2024-20929Medium (6.5)0.32%—Feb 17, 2024
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows…
CVE-2024-20915Medium (5.3)0.49%—Feb 17, 2024
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login - SSO). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows…
CVE-2023-21978Medium (6.5)0.38%—Apr 18, 2023
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: GUI). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged…
CVE-2021-2314High (8.1)0.99%—Apr 22, 2021
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Profiles). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability…
CVE-2020-14840Medium (4.7)0.98%—Oct 21, 2020
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability…
CVE-2020-14635Medium (5.3)1.2%—Jul 15, 2020
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Logging). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows…
CVE-2020-14554Medium (4.7)0.98%—Jul 15, 2020
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability…
CVE-2019-3027Medium (5.3)1.6%—Oct 16, 2019
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login Help). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows…
CVE-2019-2761Low (3.7)1.1%—Jul 23, 2019
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.8. Difficult to…
CVE-2019-2621Medium (4.7)1.0%—Apr 23, 2019
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and…
CVE-2018-3244Medium (5.3)1.9%—Oct 17, 2018
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and…
CVE-2018-3138High (8.2)2.0%—Oct 17, 2018
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System5
  2. T1190 Exploit Public-Facing Application5
  3. T1210 Exploitation of Remote Services5
  4. T1068 Exploitation for Privilege Escalation3
  5. T1059 Command and Scripting Interpreter1
  6. T1565.002 Transmitted Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Oracle