CVE-2025-30708

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 17, 2025
CWE ID 732

Summary

CVE-2025-30708 is a vulnerability affecting the Oracle User Management component of Oracle E-Business Suite, specifically versions 12.2.4 to 12.2.14. This issue allows unauthenticated attackers with network access via HTTP to compromise Oracle User Management. Successful exploitation can result in unauthorized access to critical data or complete access to all Oracle User Management accessible data, posing a significant confidentiality risk. The Base Score of this vulnerability, according to the Common Vulnerability Scoring System version 3.1, is 7.5. Attacks can be carried out without user interaction and do not require any specific privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share