First published: Tue Apr 15 2025(Updated: )
Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Teleservice accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Teleservice | >=12.2.3<=12.2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30717 is considered an easily exploitable vulnerability affecting Oracle Teleservice.
To fix CVE-2025-30717, apply the latest security patch released by Oracle for affected versions.
CVE-2025-30717 affects Oracle Teleservice versions 12.2.3 through 12.2.14.
CVE-2025-30717 can be exploited by low privileged attackers with network access via HTTP.
The impacted component in Oracle E-Business Suite is the Service Diagnostics Scripts.