Hackers Target Unpatched Flaws in Oracle E
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-30739 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. While the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data as well as unauthorized read access to a subset of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N). NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2025-30743 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Lease and Finance Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Lease and Finance Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2025-30744 | Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Field Service. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Mobile Field Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Mobile Field Service accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2025-30745 | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle MES for Process Manufacturing accessible data as well as unauthorized read access to a subset of Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2025-30746 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iStore accessible data as well as unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2025-50071 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N). NVD description · AI analysis pending | 6.4 | <1% |
| — | ||
| CVE-2025-50090 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2025-50105 +1 in the same advisory: …50107 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). NVD description · AI analysis pending | 8.1 group max | <1% |
| — |
Full article522 words · extracted from infosecurity-magazine.com · click to collapse
Written by
Oracle has advised customers that hackers may be exploiting vulnerabilities in unpatched instances of its E-Business Suite (EBS).
This follows a warning by the Google Threat Intelligence Group (GTIG) that an individual or group of hackers were sending extortion emails to executives in several companies, claiming to have stolen sensitive data from Oracle’s EBS.
Oracle is aware that some Oracle EBS customers have received extortion emails, Rob Duhart, Oracle Security’s CSO, confirmed in a statement published October 2.
“Our ongoing investigation has found the potential use of previously identified vulnerabilities that are addressed in the July 2025 Critical Patch Update,” said Duhart, urging customers to apply the patches.
Nine Oracle E-Business Suite Flaws to Patch Now
Oracle’s July 2025 critical patch update was a major security advisory where the business software provider released patches for 309 vulnerabilities across its product range.
These included nine flaws affecting its E-Business Suite. Three are critical and three others are exploitable remotely without authentication.
Here is the full list, from most to least severe:
- CVE-2025-30743 (CVSS: 8.1): vulnerability in Oracle Lease and Finance Management, no remote exploit without authentication
- CVE-2025-30744 (CVSS: 8.1): vulnerability in Oracle Mobile Field Service, no remote exploit without authentication
- CVE-2025-50105 (CVSS: 8.1): vulnerability in Oracle Universal Work Queue, no remote exploit without authentication
- CVE-2025-50071 (CVSS: 6.4): vulnerability in Oracle Applications Framework, no remote exploit without authentication
- CVE-2025-30746 (CVSS: 6.1): vulnerability in Oracle iStore, possibility of remote exploit without authentication
- CVE-2025-30745 (CVSS: 6.1): vulnerability in Oracle MES for Process Manufacturing, possibility of remote exploit without authentication
- CVE-2025-50107 (CVSS: 6.1): vulnerability in Oracle Universal Work Queue, possibility of remote exploit without authentication
- CVE-2025-30739 (CVSS: 5.5): vulnerability in Oracle CRM Technical Foundation, no remote exploit without authentication
- CVE-2025-50090 (CVSS: 5.4): vulnerability in Oracle Applications Framework, no remote exploit without authentication
Google Probes Large-Scale Email Extortion Campaign
Researchers from Mandiant and GTIG contacted Infosecurity on October 2, saying they were investigating a large-scale email campaign linked to hundreds of compromised accounts.
Charles Carmakal, CTO of Mandiant at Google Cloud, noted that the campaign appears to be high-volume, with preliminary analysis tying at least one of the accounts to FIN11, a financially motivated threat group known for ransomware attacks and extortion schemes.
While the investigation is ongoing, the evidence so far suggests the attackers may be leveraging established cybercriminal infrastructure.
The malicious emails include contact details that match addresses listed on the Clop ransomware group’s data leak site (DLS), hinting at a possible connection to the notorious gang.
However, Carmakal cautioned that this does not confirm Clop’s direct involvement, only that the attackers are exploiting the group’s reputation to amplify pressure on victims.
Such tactics are common in financially driven cybercrime, where threat actors often impersonate or mimic well-known ransomware brands to enhance credibility and coercion.
Given the complexities of attribution in cybercrime, Carmakal emphasized that the campaign could be the work of copycats rather than Clop itself.
He advised affected organizations to proactively investigate their systems for signs of compromise, as the use of Clop’s branding may be a deliberate strategy to maximize intimidation.
Read more: Fraudsters Impersonate Clop Ransomware to Extort Businesses
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/hackers-flaws-oracle-ebs/