CVE-2025-30727

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 28, 2025
CWE ID 306

Summary

CVE-2025-30727 is a critical vulnerability affecting Oracle E-Business Suite's iSurvey Module (Oracle Scripting component) versions 12.2.3 to 12.2.14. This issue permits unauthenticated attackers, with only network access via HTTP, to compromise the Oracle Scripting functionality. The exploitation of this flaw could lead to a complete takeover of the affected system, posing significant risks to confidentiality, integrity, and availability. The CVSS Base Score stands at 9.8. (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle E-business Suite 12

Affected Vendors

  • Oracle