CVE-2025-30692

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 21, 2025
CWE ID 284

Summary

CVE-2025-30692 is a vulnerability affecting Oracle iSupplier Portal, a component of Oracle E-Business Suite (versions 12.2.7 to 12.2.14). This issue allows a low-privileged attacker with network access to compromise the portal via HTTP. Successfully exploited attacks can lead to unauthorized access to critical data, potentially granting the attacker complete access to all Oracle iSupplier Portal data. The vulnerability has a CVSS 3.1 Base Score of 6.5 for Confidentiality impacts. Attackers can exploit this easily and locally (AV:N/AC:L/PR:L), without user interaction (UI:N), and the severity is considered medium (S:U).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share