CVE-2016-3447: Oracle Applications Framework

Medium severity, CVSS 6.9. EPSS: 1.2% chance of exploitation in the next 30 days.

Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to OAF Core.

Affected products

  • Oracle Applications Framework: version 12.1.3 only; version 12.2.3 only; version 12.2.4 only; version 12.2.5 only

Published 2016-04-21. Last modified 2026-06-17.