Vulnerability in Oracle Scripting of Oracle E-Business Suite
CVE-2025-61753

6.1MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-61753?

A vulnerability has been identified in the Oracle Scripting component of the Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.14. This vulnerability allows an unauthenticated attacker with network access to compromise Oracle Scripting functionalities. While direct exploitation requires human interaction from someone other than the attacker, successful engagement may lead to unauthorized updates, inserts, or deletions of accessible data. Moreover, it could grant unauthorized read access to sensitive information. Due to its nature, the implications of this vulnerability extend beyond Oracle Scripting, potentially impacting other integrated products.

Affected Version(s)

Oracle Scripting 12.2.3 <= 12.2.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.