
CVE-2017-3366
https://notcve.org/view.php?id=CVE-2017-3366
27 Jan 2017 — Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional... • http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html •

CVE-2017-3367
https://notcve.org/view.php?id=CVE-2017-3367
27 Jan 2017 — Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional... • http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html •

CVE-2016-3533 – Oracle E-Business Suite 12.2 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2016-3533
21 Jul 2016 — Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Search. NOTE: the previous information is from the July 2016 CPU. Oracle has not commented on third-party claims that this issue involves multiple open redirect vulnerabilities, which allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vec... • http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html •

CVE-2016-3542 – Oracle Knowledge Management 12.1.1 < 12.2.5 - XML External Entity Leading To Remote Code Execution
https://notcve.org/view.php?id=CVE-2016-3542
21 Jul 2016 — Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote administrators to affect confidentiality and integrity via unknown vectors. Vulnerabilidad no especificada en el componente Oracle Knowledge Management en Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4 y 12.2.5 permite a administradores remotos afectar la confidencialidad y la integridad a través de vectores desconocidos. • https://www.exploit-db.com/exploits/44041 •