CVE-2025-30726

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 21, 2025
CWE ID 284

Summary

CVE-2025-30726 is a newly identified vulnerability affecting the Oracle Application Object Library component of Oracle E-Business Suite, versions 12.2.3 to 12.2.14. This vulnerability, which has a base score of 5.3 (Confidentiality impacts) according to CVSS 3.1, allows unauthenticated attackers with network access to compromise Oracle Application Object Library via HTTP. Successful exploitation could grant attackers unauthorized read access to a subset of the data accessible through the affected component. It is essential for organizations using these versions to apply the necessary patches to mitigate this vulnerability and prevent potential data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle Application Object Library

Affected Vendors

  • Oracle