PT-2025-29597 · Oracle · Oracle Mes For Process Manufacturing
Published
2025-07-15
·
Updated
2025-10-04
·
CVE-2025-30745
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle MES for Process Manufacturing versions 12.2.12 through 12.2.13
Description
An issue exists in the Device Integration component of Oracle MES for Process Manufacturing, part of Oracle E-Business Suite. This relates to cross-site request forgery. A remote, unauthenticated attacker with network access via HTTP can compromise the system. Successful exploitation requires interaction from an individual other than the attacker, and may impact other products. Successful attacks can lead to unauthorized data modification, insertion, deletion, and read access to Oracle MES for Process Manufacturing data.
Recommendations
Oracle MES for Process Manufacturing version 12.2.12: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Oracle MES for Process Manufacturing version 12.2.13: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Mes For Process Manufacturing