« Back to list

Oracle

Oracle Workflow: vulnerabilities and CVEs

Oracle Workflow has 24 published vulnerabilities, 15 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs24
Last 12 months15
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-70931High (8.1)0.38%—Aug 18, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low…
CVE-2026-70927High (7.5)0.47%—Aug 18, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows…
CVE-2026-70926Critical (9.8)0.51%—Aug 18, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows…
CVE-2026-60830Medium (6.5)0.35%—Aug 18, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker…
CVE-2026-62547High (8.1)0.39%—Jul 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows…
CVE-2026-61278Medium (6.3)0.26%—Jul 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low…
CVE-2026-61247Medium (4.8)0.27%—Jul 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows…
CVE-2026-60780High (8.1)0.39%—Jul 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows…
CVE-2026-60575Medium (6.3)0.26%—Jul 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low…
CVE-2026-60149Medium (5.2)0.13%—Jul 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high…
CVE-2026-60144Low (3.6)0.11%—Jul 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low…
CVE-2026-60143High (7.3)0.31%—Jul 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows…
CVE-2026-34302Medium (5.5)0.33%—Apr 21, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged…
CVE-2026-21959Medium (4.9)0.36%—Jan 20, 2026
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged…
CVE-2025-53052Medium (6.1)0.23%—Oct 21, 2025
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows…
CVE-2025-21541Medium (5.4)0.27%—Jan 21, 2025
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low…
CVE-2024-21071Critical (9.1)0.72%—Apr 16, 2024
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high…
CVE-2022-21567High (7.5)0.93%—Jul 19, 2022
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker…
CVE-2021-2343Medium (4.3)0.86%—Jul 21, 2021
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability…
CVE-2021-2015High (8.2)1.2%—Jan 20, 2021
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker…
CVE-2020-2753Medium (5.3)1.1%—Apr 15, 2020
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability…
CVE-2019-2925Medium (4.3)1.2%—Oct 16, 2019
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated…
CVE-2006-1884High (10)3.8%—Apr 20, 2006
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
CVE-2006-0552High (7.5)4.8%—Feb 4, 2006
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application5
  2. T1078 Valid Accounts3
  3. T1565.002 Transmitted Data Manipulation2
  4. T1210 Exploitation of Remote Services1
  5. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Oracle