First published: Tue Apr 15 2025(Updated: )
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle iStore | >=12.2.3<=12.2.14 | |
Oracle iStore | >=12.2.3<=12.2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30707 is considered an easily exploitable vulnerability that allows unauthenticated attackers to compromise Oracle iStore.
To fix CVE-2025-30707, it is recommended to apply the latest security patches provided by Oracle for Oracle iStore versions 12.2.3 through 12.2.14.
CVE-2025-30707 affects users of Oracle iStore versions 12.2.3 to 12.2.14 within the Oracle E-Business Suite.
Yes, CVE-2025-30707 can be exploited remotely by unauthenticated attackers with network access via HTTP.
CVE-2025-30707 specifically affects the User Management component of the Oracle iStore product.