CVE-2025-21506

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 863

Summary

CVE-2025-21506 is a vulnerability affecting Oracle Project Foundation in Oracle E-Business Suite (Technology Foundation component). Affected versions include 12.2.3 to 12.2.13. This issue allows a low-privileged attacker with network access via HTTP to compromise Oracle Project Foundation. Successful exploitation may lead to unauthorized creation, deletion, or modification of critical data or access to all Oracle Project Foundation data. The confidentiality and integrity of critical data are at risk, with a CVSS 3.1 Base Score of 8.1. Attacks require low attack complexity and can be carried out with network access, making this a potentially serious concern.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share