CVE-2025-30727
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 15, 2025
Updated: Apr 28, 2025
CWE ID 306
Summary
CVE-2025-30727 is a critical vulnerability affecting Oracle E-Business Suite's iSurvey Module (Oracle Scripting component) versions 12.2.3 to 12.2.14. This issue permits unauthenticated attackers, with only network access via HTTP, to compromise the Oracle Scripting functionality. The exploitation of this flaw could lead to a complete takeover of the affected system, posing significant risks to confidentiality, integrity, and availability. The CVSS Base Score stands at 9.8. (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle E-business Suite 12
Affected Vendors
- Oracle