CVE-2025-21541 is a low-privileged vulnerability affecting Oracle Workflow within Oracle E-Business Suite versions 12.2.3 through 12.2.14, specifically impacting Admin Screens and Grants UI. This easily exploitable flaw, accessible via HTTP network access, allows unauthorized modification or deletion of some data, and unauthorized read access to a subset of data. With a CVSS 3.1 Base Score of 5.4 (Medium), it primarily impacts confidentiality and integrity. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, there is significant community discussion and media coverage, including reports of an emergency patch issued due to exploitation by the Cl0p ransomware gang.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.14CPE matchmatch criteria | cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.