Critical Vulnerability In Oracle E-Business Suite’s Marketing Product Allows Full Access To Attackers
Oracle has announced two critical vulnerabilities in its E-Business Suite's Marketing product that could allow remote attackers to gain full control.
Oracle has announced two critical vulnerabilities in its E-Business Suite's Marketing product that could allow remote attackers to gain full control.
Identified as CVE-2025-53072 and CVE-2025-62481, these vulnerabilities impact the Marketing Administration component and have been assigned a CVSS score of 9.8, denoting them as highly severe.
Organizations utilizing Oracle’s suite for customer relationship management and marketing automation must urgently apply patches to mitigate risks such as data breaches and system takeovers.
The vulnerabilities arise from how the Marketing Administration processes HTTP requests. Exploitation requires only network access, with no need for special privileges or user interaction.
If exploited, these flaws allow full compromise of the Oracle Marketing module, granting attackers extensive access to confidentiality, integrity, and availability.
Both vulnerabilities affect Oracle Marketing versions 12.2.3 through 12.2.14, with no mitigations available apart from applying recent security patches.
Oracle has announced two critical vulnerabilities in its E-Business Suite's Marketing product that could allow remote attackers to gain full control.
The CVSS 3.1 vector for each vulnerability (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a network attack vector, low attack complexity, no required privileges, no user interaction, unchanged scope, and high impacts across confidentiality, integrity, and availability.
CVE ID Component Attack Vector Requires Auth? CVSS 3.1 Score Attack Complexity Privileges Required User Interaction Scope Confidentiality Impact Integrity Impact Availability Impact Affected Versions
CVE-2025-53072 Marketing Administration HTTP (Network) No 9.8 Low None None Unchanged High High High 12.2.3-12.2.14
CVE-2025-62481 Marketing Administration HTTP (Network) No 9.8 Low None None Unchanged High High High 12.2.3-12.2.14
The vulnerabilities have surfaced amid increased supply chain attacks targeting enterprise tools. Businesses in sectors such as retail, finance, and e-commerce that depend on Oracle E-Business Suite for core marketing functions may face exposure risks, leading to potential regulatory fines under frameworks like GDPR or CCPA.
Oracle advises immediate patching through its Critical Patch Update for October 2025 , accessible via My Oracle Support.
In the meantime, recommendations include network segmentation, employing web application firewalls configured for HTTP anomalies, and monitoring for unusual activity in the Marketing Administration module.
Cybersecurity experts have noted the possibility of exploit code emerging on dark web forums, given the high stakes involved.
While no active exploitation has been reported, the opportunity for defense is closing swiftly.
Based on reporting by Cyber Security News.
