Vulnerability in Oracle E-Business Suite's iSurvey Module
CVE-2025-30727

9.8CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability exists in the iSurvey Module of Oracle E-Business Suite (version 12.2.3 to 12.2.14) that can be easily exploited by unauthenticated attackers with network access via HTTP. This security flaw may lead to unauthorized takeover of the Oracle Scripting product, compromising the confidentiality, integrity, and availability of affected systems. Organizations utilizing these versions should prioritize addressing this vulnerability to safeguard sensitive data and maintain operational security.

Affected Version(s)

Oracle Scripting 12.2.3 <= 12.2.14

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.