Security Flaw in Oracle Mobile Field Service of Oracle E-Business Suite
CVE-2025-30744

8.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-30744?

A vulnerability exists in the Oracle Mobile Field Service component of the Oracle E-Business Suite that can be easily exploited by low-privileged attackers with network access via HTTP. This flaw allows unauthorized individuals to create, delete, or modify critical data within the service and gain unauthorized access to all data accessible through Oracle Mobile Field Service. The affected supported versions range from 12.2.3 to 12.2.13, highlighting the need for immediate attention to mitigate potential risks associated with unauthorized data manipulation.

Affected Version(s)

Oracle Mobile Field Service 12.2.3 <= 12.2.13

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.