Oracle E-Business Suite Vulnerability in Process Manufacturing Device Integration
CVE-2025-30745

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-30745?

A vulnerability exists in the Device Integration component of Oracle MES for Process Manufacturing within the Oracle E-Business Suite, affecting versions 12.2.12 and 12.2.13. This flaw allows unauthenticated attackers with network access via HTTP to potentially compromise the system. While successful exploitation requires human interaction from a user other than the attacker, the ramifications can include unauthorized updates, inserts, or deletions to critical data. Furthermore, it may enable unauthorized read access to sensitive data within the system, posing significant risks to information confidentiality and integrity.

Affected Version(s)

Oracle MES for Process Manufacturing 12.2.12 <= 12.2.13

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.