Unauthorized Data Access in Oracle E-Business Suite Preferences Component
CVE-2025-21582

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 April 2025

What is CVE-2025-21582?

A vulnerability exists within the Preferences component of the Oracle CRM Technical Foundation of Oracle E-Business Suite, affecting versions 12.2.3 to 12.2.14. An unauthenticated attacker with network access via HTTP can exploit this vulnerability. Successful exploitation requires human interaction from an impacted user, which may lead to significant data compromises. Unauthorized actions could result in the ability to update, insert, or delete data, as well as read sensitive information, impacting the overall data integrity and confidentiality of accessible data within the Oracle CRM Technical Foundation.

Affected Version(s)

Oracle CRM Technical Foundation 12.2.3 <= 12.2.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.