Skip to main content
All vendors

Oracle security briefs

14 published alerts for Oracle products and services.

Actively exploited (KEV)

CVE-2026-46817

Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-46817). Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CISA remediation due date: 2026-07-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)Ransomware

CVE-2026-35273

Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-35273). Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. CISA remediation due date: 2026-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-61884

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Oracle E-Business Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-61884). Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication. CISA remediation due date: 2025-11-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-61882

Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-61882). Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-21587

Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-21587). Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. CISA remediation due date: 2023-02-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-0431

Oracle JRE Sandbox Bypass Vulnerability

Oracle Java Runtime Environment (JRE) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0431). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-0422

Oracle JRE Remote Code Execution Vulnerability

Oracle Java Runtime Environment (JRE) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-0422). A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2012-1710

Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1710). Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. CISA remediation due date: 2022-06-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2013-2465

Oracle Java SE Unspecified Vulnerability

Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2013-2465). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D CISA remediation due date: 2022-04-18. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2012-4681

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-4681). The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2012-1723

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1723). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2012-0507

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Oracle Java SE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-0507). An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. CISA remediation due date: 2022-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-10271

Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-10271). Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. CISA remediation due date: 2022-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-2725

Oracle WebLogic Server, Injection vulnerability

Oracle WebLogic Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-2725). Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). CISA remediation due date: 2022-07-10. If you need help checking exposure, call (864) 335-9223.