PT-2025-29597 · Oracle · Oracle Mes For Process Manufacturing

Published

2025-07-15

·

Updated

2025-10-04

·

CVE-2025-30745

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle MES for Process Manufacturing versions 12.2.12 through 12.2.13
Description An issue exists in the Device Integration component of Oracle MES for Process Manufacturing, part of Oracle E-Business Suite. This relates to cross-site request forgery. A remote, unauthenticated attacker with network access via HTTP can compromise the system. Successful exploitation requires interaction from an individual other than the attacker, and may impact other products. Successful attacks can lead to unauthorized data modification, insertion, deletion, and read access to Oracle MES for Process Manufacturing data.
Recommendations Oracle MES for Process Manufacturing version 12.2.12: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Oracle MES for Process Manufacturing version 12.2.13: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

BDU:2025-08719
CVE-2025-30745

Affected Products

Oracle Mes For Process Manufacturing