CVE-2025-30720

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025

Summary

CVE-2025-30720 is a vulnerability affecting Oracle E-Business Suite's Oracle Configurator product (versions 12.2.3-12.2.14). This issue allows unauthenticated attackers to exploit Oracle Configurator via HTTP, leading to potential data compromise. Successful attacks require human interaction and may impact other products. The vulnerability grants unauthorized access for update, insert, or delete actions on some Configurator data, as well as unauthorized read access to a subset of it. The Base Score is 6.1 (Confidentiality and Integrity impacts). This easily exploitable vulnerability should be addressed promptly to minimize potential risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share