cbcvebase.
CVE-2025-30727
published 2025-04-15

CVE-2025-30727: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.14…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.49%
38.6th percentile
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

2 ranges
VendorProductVersion rangeFixed in
oraclee-business_suite12.2.3 – 12.2.14
oracle_corporationoracle_scripting12.2.3 – 12.2.14

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in Oracle E-Business Suite, Oracle Scripting product, iSurvey Module component — network-accessible via HTTP with no authentication required (PR:N/UI:N), making HTTP traffic to EBS iSurvey endpoints a detection focus
  • Affected versions are Oracle E-Business Suite 12.2.3 through 12.2.14 — inventory and patch-status checks should target this version range
  • Successful exploitation results in full takeover (C:H/I:H/A:H) — monitor for anomalous unauthenticated HTTP requests to Oracle Scripting/iSurvey Module endpoints as a high-priority alert
  • ·No authentication or user interaction is required, meaning perimeter controls (firewall rules restricting HTTP access to EBS iSurvey endpoints from untrusted networks) are a critical compensating control until patching
  • ·Fix is addressed in Oracle's April 2025 Critical Patch Update (cpuapr2025) — systems not yet patched to the fixed release remain fully exposed

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.