Vulnerability in Oracle Applications Framework for E-Business Suite by Oracle
CVE-2025-50071

6.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-50071?

A vulnerability within the Oracle Applications Framework component of Oracle E-Business Suite permits low-privileged attackers with network access to HTTP to exploit the system. This situation can lead to unauthorized access for updating, inserting, or deleting data that the framework manages. Additionally, attackers may gain inappropriate read access to certain data. The vulnerability's broad scope indicates potential impacts across other Oracle products, making it essential for organizations to implement security measures to safeguard against such threats.

Affected Version(s)

Oracle Applications Framework 12.2.3 <= 12.2.14

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50071 : Vulnerability in Oracle Applications Framework for E-Business Suite by Oracle