CVE-2025-30732

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 21, 2025
CWE ID 284

Summary

CVE-2025-30732 is a vulnerability in Oracle E-Business Suite's Oracle Application Object Library (12.2.3-12.2.14), which is easily exploitable by unauthenticated attackers with network access via HTTP. This issue allows attackers to compromise the Oracle Application Object Library, potentially leading to significant impacts on additional products. Successful attacks require human interaction and can result in unauthorized update, insert, or delete access to some data, as well as unauthorized read access to a subset of data. The CVSS Base Score is 6.1 for Confidentiality and Integrity impacts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle Application Object Library

Affected Vendors

  • Oracle