oracle security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect oracle products.
Vulnios monitors oracle CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent oracle security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2021-2101 — oracle — one-to-one_fulfillment
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily explo
criticalCVE-2021-2101Critical Vulnerability: CVE-2021-2075 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1
criticalCVE-2021-2075Critical Vulnerability: CVE-2021-2100 — oracle — one-to-one_fulfillment
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily explo
criticalCVE-2021-2100Critical Vulnerability: CVE-2021-2108 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability all
criticalCVE-2021-2108Critical Vulnerability: CVE-2021-1994 — oracle — enterprise_repository, weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulner
criticalCVE-2021-1994Critical Vulnerability: CVE-2021-2029 — oracle — scripting
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.8. Easily exploitable vulner
criticalCVE-2021-2029Critical Vulnerability: CVE-2020-14756 — oracle — coherence, utilities_framework
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.
criticalCVE-2020-14756Critical Vulnerability: CVE-2021-2047 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, and 12.2.1.3.0. Easily ex
criticalCVE-2021-2047Critical Vulnerability: CVE-2021-2064 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability all
criticalCVE-2021-2064Critical Vulnerability: CVE-2020-14805 — oracle — e-business_suite_secure_enterprise_search
Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.1.3 and 12.
criticalCVE-2020-14805Critical Vulnerability: CVE-2020-14876 — oracle — trade_management
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily explo
criticalCVE-2020-14876Critical Vulnerability: CVE-2020-14825 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vu
criticalCVE-2020-14825Critical Vulnerability: CVE-2020-14859 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.
criticalCVE-2020-14859Critical Vulnerability: CVE-2020-14841 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.
criticalCVE-2020-14841Critical Vulnerability: CVE-2020-14875 — oracle — marketing
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily ex
criticalCVE-2020-14875Critical Vulnerability: CVE-2020-14855 — oracle — universal_work_queue
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). The supported version that is affected is 12.1.3. Easily exploitable vuln
criticalCVE-2020-14855Critical Vulnerability: CVE-2020-14645 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.
criticalCVE-2020-14645Critical Vulnerability: CVE-2020-14658 — oracle — marketing
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploit
criticalCVE-2020-14658Critical Vulnerability: CVE-2020-14687 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vu
criticalCVE-2020-14687Critical Vulnerability: CVE-2020-14701 — oracle — sd-wan_aware
Vulnerability in the Oracle SD-WAN Aware product of Oracle Communications Applications (component: User Interface). The supported version that is affected is 8.2. Easily exploitable vulnerability allo
criticalCVE-2020-14701Critical Vulnerability: CVE-2020-14705 — oracle — goldengate
Vulnerability in the Oracle GoldenGate product of Oracle GoldenGate (component: Process Management). The supported version that is affected is Prior to 19.1.0.0.0. Easily exploitable vulnerability all
criticalCVE-2020-14705Critical Vulnerability: CVE-2020-14665 — oracle — trade_management
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Invoice). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulne
criticalCVE-2020-14665Critical Vulnerability: CVE-2020-14598 — oracle — customer_relationship_management_gateway_for_mobile_devices
Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily
criticalCVE-2020-14598Critical Vulnerability: CVE-2020-14599 — oracle — customer_relationship_management_gateway_for_mobile_devices
Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily
criticalCVE-2020-14599Critical Vulnerability: CVE-2020-14625 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vu
criticalCVE-2020-14625Critical Vulnerability: CVE-2020-14606 — oracle — sd-wan_edge
Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications Applications (component: User Interface). Supported versions that are affected are 8.2 and 9.0. Easily exploitable vulnerabilit
criticalCVE-2020-14606Critical Vulnerability: CVE-2020-2931 — oracle — knowledge
Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Web Applications - InfoCenter). Supported versions that are affected are 8.6.0-8.6.3. Easily exploitable vulnerability all
criticalCVE-2020-2931Critical Vulnerability: CVE-2020-2950 — oracle — business_intelligence
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.
criticalCVE-2020-2950Critical Vulnerability: CVE-2020-2961 — oracle — enterprise_manager_base_platform
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework (Oracle OHS)). Supported versions that are affected are 13.2.0.0 and 13.3.0.0
criticalCVE-2020-2961Critical Vulnerability: CVE-2020-2953 — oracle — retail_customer_management_and_segmentation_foundation
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 18.0. Easily
criticalCVE-2020-2953Critical Vulnerability: CVE-2020-2915 — oracle — coherence
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, CacheStore, Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.
criticalCVE-2020-2915Critical Vulnerability: CVE-2020-2884 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily ex
criticalCVE-2020-2884Critical Vulnerability: CVE-2020-2801 — oracle — weblogic_server, jdk
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily ex
criticalCVE-2020-2801Critical Vulnerability: CVE-2020-2733 — oracle — jd_edwards_enterpriseone_tools
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerabilit
criticalCVE-2020-2733Critical Vulnerability: CVE-2020-2791 — oracle — knowledge
Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported versions that are affected are 8.6.0-8.6.2. Easily exploitable vulnerability allow
criticalCVE-2020-2791Critical Vulnerability: CVE-2020-2586 — oracle — human_resources
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily expl
criticalCVE-2020-2586Critical Vulnerability: CVE-2020-2587 — oracle — human_resources
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily expl
criticalCVE-2020-2587Critical Vulnerability: CVE-2020-2546 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily
criticalCVE-2020-2546Critical Vulnerability: CVE-2019-3020 — oracle — primavera_p6_enterprise_project_portfolio_management
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 15.1.0-15.2.1
criticalCVE-2019-3020Critical Vulnerability: CVE-2019-3025 — oracle — hospitality_res_3700
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported version that is affected is 5.7. Difficult to exploit vulnerability allows unauthenti
criticalCVE-2019-3025Critical Vulnerability: CVE-2019-2904 — oracle — application_testing_suite, banking_enterprise_collections
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploi
criticalCVE-2019-2904Critical Vulnerability: CVE-2019-2856 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Application Container - JavaEE). Supported versions that are affected is 12.2.1.3.0. Easily exploitable
criticalCVE-2019-2856Critical Vulnerability: CVE-2019-2828 — oracle — field_service
Vulnerability in the Oracle Field Service component of Oracle E-Business Suite (subcomponent: Wireless). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.8. Easily exploitabl
criticalCVE-2019-2828Critical Vulnerability: CVE-2019-2775 — oracle — payments
Vulnerability in the Oracle Payments component of Oracle E-Business Suite (subcomponent: File Transmission). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.8. Easily exploi
criticalCVE-2019-2775Critical Vulnerability: CVE-2019-2729 — oracle — communications_diameter_signaling_router, communications_network_integrity
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily e
criticalCVE-2019-2729Critical Vulnerability: CVE-2019-2638 — oracle — general_ledger
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3,
criticalCVE-2019-2638Critical Vulnerability: CVE-2019-2646 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily
criticalCVE-2019-2646Critical Vulnerability: CVE-2019-2517 — oracle — database_server
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having
criticalCVE-2019-2517Critical Vulnerability: CVE-2019-2658 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploi
criticalCVE-2019-2658Critical Vulnerability: CVE-2019-2633 — oracle — work_in_process
Vulnerability in the Oracle Work in Process component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2
criticalCVE-2019-2633Critical Vulnerability: CVE-2019-2645 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. E
criticalCVE-2019-2645Critical Vulnerability: CVE-2019-2699 — oracle — jdk, jre
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). The supported version that is affected is Java SE: 8u202. Difficult to exploit vulnerability allows unauthenticate
criticalCVE-2019-2699Critical Vulnerability: CVE-2019-2702 — oracle — hospitality_cruise_dining_room_management
Vulnerability in the Oracle Hospitality Cruise Dining Room Management component of Oracle Hospitality Applications (subcomponent: Web Service). The supported version that is affected is 8.0.80. Easily
criticalCVE-2019-2702Critical Vulnerability: CVE-2019-2453 — oracle — e-business_suite
Vulnerability in the Oracle Performance Management component of Oracle E-Business Suite (subcomponent: Performance Management Plan). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3.
criticalCVE-2019-2453Critical Vulnerability: CVE-2019-2489 — oracle — e-business_suite
Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: OCM Query). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2
criticalCVE-2019-2489Critical Vulnerability: CVE-2018-3252 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily
criticalCVE-2018-3252Critical Vulnerability: CVE-2018-3245 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily
criticalCVE-2018-3245Critical Vulnerability: CVE-2018-3259 — oracle — database_server
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated
criticalCVE-2018-3259Critical Vulnerability: CVE-2018-3294 — oracle — vm_virtualbox
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.20. Easily exploitable vulnerability allows lo
criticalCVE-2018-3294Critical Vulnerability: CVE-2018-3197 — oracle — weblogic_server
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). The supported version that is affected is 12.1.3.0. Easily exploitable vulnerabil
criticalCVE-2018-3197
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track oracle exposure across your environment
Vulnios automatically cross-references your asset inventory against new oracle CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan