Configurator

Vendor:

First CVE: Apr 1, 2002 · Active for 24 years

17
Total CVEs
More Total CVEs than 94% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
5.9%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Configurator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2002
24 years ago
Most Recent CVE
Apr 21, 2026
97 days ago

CVE Severity & Scoring

Configurator17 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network13 (76.5%)
Unknown4 (23.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (76.5%)
High0 (0.0%)
Unknown4 (23.5%)
User Interaction
None6 (35.3%)
Unknown4 (23.5%)
Required7 (41.2%)
Privileges Required
Low1 (5.9%)
High0 (0.0%)
None12 (70.6%)
Unknown4 (23.5%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu
Oct 12, 20257.598YESYES
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: UI Servlet). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vul
Jan 19, 20228.126NONO
Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: UI Servlet). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerab
Jan 20, 20218.225NONO
Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: UI Servlet). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerab
Jan 20, 20218.224NONO
Vulnerability in the Oracle Configurator product of Oracle Supply Chain (component: UI Servlet). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerab
Jan 20, 20218.224NONO
Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1, and 12.2 allows remote attackers to affect confidentiality and in
Apr 21, 20168.224NONO
Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with
Apr 1, 20027.524NONO
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (
Apr 1, 20026.822NONO
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitabl
Apr 21, 20266.121NONO
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerab
Apr 15, 20257.521NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
1 CVE
5.9% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.9% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Configurator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
12.297.11.5%00
12.197.11.5%00
11i27.25.3%00
11.5.10.225.01.8%00