CVE-2025-30728 is an easily exploitable vulnerability affecting the Core component of Oracle Configurator within Oracle E-Business Suite versions 12.2.3 through 12.2.14. This unauthenticated network vulnerability allows attackers via HTTP to gain unauthorized access to critical or all data accessible by Oracle Configurator. With a CVSS 3.1 Base Score of 7.5 (High), the primary impact is high confidentiality compromise. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is there any indication of active exploitation, community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.14CPE matchmatch criteria | cpe:2.3:a:oracle:configurator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.