Unauthenticated Remote Code Execution in Oracle Marketing by Oracle
CVE-2025-62481
9.8CRITICAL
What is CVE-2025-62481?
A vulnerability has been identified in the Oracle Marketing component of Oracle E-Business Suite, specifically in versions ranging from 12.2.3 to 12.2.14. This vulnerability allows an unauthenticated attacker with network access via HTTP to execute arbitrary code, potentially compromising Oracle Marketing. Successful exploitation can lead to a complete takeover of the application, with far-reaching impacts on system confidentiality, integrity, and availability. Organizations using affected versions need to assess their security posture and apply the necessary updates to mitigate the risk associated with this vulnerability.
Affected Version(s)
Oracle Marketing 12.2.3 <= 12.2.14