Unauthorized Data Access in Oracle E-Business Suite Preferences Component
CVE-2025-21582
6.1MEDIUM
What is CVE-2025-21582?
A vulnerability exists within the Preferences component of the Oracle CRM Technical Foundation of Oracle E-Business Suite, affecting versions 12.2.3 to 12.2.14. An unauthenticated attacker with network access via HTTP can exploit this vulnerability. Successful exploitation requires human interaction from an impacted user, which may lead to significant data compromises. Unauthorized actions could result in the ability to update, insert, or delete data, as well as read sensitive information, impacting the overall data integrity and confidentiality of accessible data within the Oracle CRM Technical Foundation.
Affected Version(s)
Oracle CRM Technical Foundation 12.2.3 <= 12.2.14