Oracle

Configurator

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.18%
  • Veröffentlicht 15.04.2020 14:15:32
  • Zuletzt bearbeitet 21.11.2024 05:26:29

Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: Installation). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t...

  • EPSS 1.49%
  • Veröffentlicht 23.04.2019 19:32:48
  • Zuletzt bearbeitet 21.11.2024 04:41:07

Vulnerability in the Oracle Configurator component of Oracle Supply Chain Products Suite (subcomponent: Active Model Generation). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker...

  • EPSS 0.39%
  • Veröffentlicht 21.04.2016 11:00:29
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1, and 12.2 allows remote attackers to affect confidentiality and integrity via vectors related to JRAD Heartbeat. NOTE: the previous info...

  • EPSS 0.32%
  • Veröffentlicht 21.01.2016 03:01:29
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 11.5.10.2, 12.1, and 12.2 allows remote attackers to affect confidentiality via unknown vectors related to UI Servlet, a different vulnerability than...

  • EPSS 0.32%
  • Veröffentlicht 21.01.2016 03:01:28
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 11.5.10.2, 12.1, and 12.2 allows remote attackers to affect confidentiality via unknown vectors related to UI Servlet, a different vulnerability than...

  • EPSS 2.09%
  • Veröffentlicht 01.04.2002 05:00:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host".

Exploit
  • EPSS 1.52%
  • Veröffentlicht 01.04.2002 05:00:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the orac...