Unauthorized Data Access Vulnerability in Oracle E-Business Suite Universal Work Queue
CVE-2025-50107

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-50107?

The vulnerability within Oracle E-Business Suite's Universal Work Queue component poses a significant risk by allowing unauthenticated attackers with network access to exploit it. Successful exploitation requires human interaction from users, potentially leading to unauthorized updates, data insertion, or deletions. This vulnerability could lead to reduced confidentiality and integrity of sensitive data, significantly affecting the security landscape of all products utilizing Oracle Universal Work Queue. Organizations must assess their risk and apply necessary mitigations to prevent such unauthorized data access.

Affected Version(s)

Oracle Universal Work Queue 12.2.5 <= 12.2.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50107 : Unauthorized Data Access Vulnerability in Oracle E-Business Suite Universal Work Queue