This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Oracle First view 2016-01-20
Product General Ledger Last view 2021-04-22
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:oracle:general_ledger:12.1.1:*:*:*:*:*:*:* 4
cpe:2.3:a:oracle:general_ledger:12.1.2:*:*:*:*:*:*:* 4
cpe:2.3:a:oracle:general_ledger:12.1.3:*:*:*:*:*:*:* 4
cpe:2.3:a:oracle:general_ledger:11.5.10.2:*:*:*:*:*:*:* 3
cpe:2.3:a:oracle:general_ledger:12.2.5:*:*:*:*:*:*:* 3
cpe:2.3:a:oracle:general_ledger:12.2.3:*:*:*:*:*:*:* 3
cpe:2.3:a:oracle:general_ledger:12.2.4:*:*:*:*:*:*:* 3
cpe:2.3:a:oracle:general_ledger:12.2.6:*:*:*:*:*:*:* 3
cpe:2.3:a:oracle:general_ledger:12.2.8:*:*:*:*:*:*:* 2
cpe:2.3:a:oracle:general_ledger:12.2.7:*:*:*:*:*:*:* 2

Related : CVE

  Date Alert Description
5.5 2021-04-22 CVE-2021-2237

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Account Hierarchy Manager). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

7.5 2020-04-15 CVE-2020-2750

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Account Hierarchy Manager). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

9.9 2019-04-23 CVE-2019-2638

Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).

7.5 2017-08-08 CVE-2017-10245

Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

4.3 2016-01-20 CVE-2016-0588

Unspecified vulnerability in the Oracle General Ledger component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Consolidation Hierarchy Viewer.

Snort® IPS/IDS

Date Description
2020-03-26 Oracle E-Business Suite TCF Server arbitrary SQL execution attempt
RuleID : 53250 - Type : POLICY-OTHER - Revision : 2
2020-03-26 Oracle E-Business Suite TCF Server access attempt
RuleID : 53249 - Type : POLICY-OTHER - Revision : 2

Nessus® Vulnerability Scanner

id Description
2017-07-20 Name: A web application installed on the remote host is affected by multiple vulner...
File: oracle_e-business_cpu_jul_2017.nasl - Type: ACT_GATHER_INFO
2016-01-21 Name: A web application installed on the remote host is affected by multiple vulner...
File: oracle_e-business_cpu_jan_2016.nasl - Type: ACT_GATHER_INFO