« Back to list

Oracle

Oracle Purchasing: vulnerabilities and CVEs

Oracle Purchasing has 14 published vulnerabilities, 12 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs14
Last 12 months12
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-87265High (8.1)0.36%—Sep 15, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-87168High (8.1)0.36%—Sep 15, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-87167High (8.1)0.36%—Sep 15, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-87166High (8.1)0.36%—Sep 15, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-87163High (8.8)0.43%—Sep 15, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-87127High (7.7)0.39%—Sep 15, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-70948High (8.8)0.43%—Aug 18, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-70947High (7.5)0.41%—Aug 18, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated…
CVE-2026-70811High (8.1)0.36%—Aug 18, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-70798High (7.8)0.16%—Aug 18, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2026-70797High (7.2)0.49%—Aug 18, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high…
CVE-2026-62491High (8.1)0.36%—Aug 18, 2026
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged…
CVE-2024-21132Medium (5.4)0.27%—Jul 16, 2024
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Approvals). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker…
CVE-2021-2262High (8.1)0.99%—Apr 22, 2021
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Endeca). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows low privileged attacker with…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services10
  2. T1005 Data from Local System8
  3. T1059 Command and Scripting Interpreter3
  4. T1068 Exploitation for Privilege Escalation2
  5. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Oracle