Skip to main content

Vendor/product archive

oracle / configurator CVEs

Beta · best-effort

17 CVEs tagged to oracle / configurator0 Critical, 10 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2026-34274

Published Apr 21, 2026

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitab…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21972

Published Jan 20, 2026

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitab…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-61884

Published Oct 12, 2025

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable v…

CVSS 7.5 · High
evidence mentions
17
Buzz score
68.4
Vendor/product tagsBeta · best-effort

CVE-2025-30728

Published Apr 15, 2025

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnera…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30720

Published Apr 15, 2025

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Orders). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulne…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21255

Published Jan 19, 2022

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: UI Servlet). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vu…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-2080

Published Jan 20, 2021

Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: UI Servlet). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnera…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-2079

Published Jan 20, 2021

Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: UI Servlet). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnera…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-2078

Published Jan 20, 2021

Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: UI Servlet). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnera…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14669

Published Jul 15, 2020

Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: UI Servlet). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnera…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2865

Published Apr 15, 2020

Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: Installation). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulne…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-2567

Published Apr 23, 2019

Vulnerability in the Oracle Configurator component of Oracle Supply Chain Products Suite (subcomponent: Active Model Generation). Supported versions that are affected are 12.1 and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3438

Published Apr 21, 2016

Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1, and 12.2 allows remote attackers to affect confidentiality and i…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0541

Published Jan 21, 2016

Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 11.5.10.2, 12.1, and 12.2 allows remote attackers to affect confidentiality vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0540

Published Jan 21, 2016

Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 11.5.10.2, 12.1, and 12.2 allows remote attackers to affect confidentiality vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1639

Published Apr 1, 2002

Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1640

Published Apr 1, 2002

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1