Vulnerability in Oracle iStore of Oracle E-Business Suite
CVE-2025-30746

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-30746?

The Oracle iStore component of Oracle E-Business Suite contains a vulnerability that allows unauthenticated attackers to exploit the shopping cart feature. This vulnerability can be triggered through network access via HTTP and requires interaction from a user other than the attacker. Successful exploitation may lead to unauthorized updates, insertions, deletions, and even reading of sensitive data accessible through Oracle iStore. The scope of the attack may extend beyond the iStore itself, impacting other connected applications and compromising data confidentiality and integrity.

Affected Version(s)

Oracle iStore 12.2.3 <= 12.2.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.