CNNVD-202510-2707 Information

CNNVD ID

CNNVD-202510-2707

CVE-2025-53041

  • CNNVD Published: 2025-10-21

Description (Chinese)

Oracle E-Business Suite是美国甲骨文(Oracle)公司的一套全面集成式的全球业务管理软件。该软件提供了客户关系管理、服务管理、财务管理等功能。iStore是其中的一个能够让商家有效地构建、部署、管理和个性化处理互联网店面的电子商务应用程序。 Oracle E-Business Suite的Oracle iStore 12.2.5版本至12.2.14版本存在安全漏洞,该漏洞源于未经验证的攻击者可通过HTTP网络访问进行攻击,可能导致未经授权的数据访问和修改。

Description (English)

Oracle E-Business Suite is a fully integrated global business management software package for Oracle. The software provides functions such as customer relationship management, service management and financial management. iStore is one of the e-commerce applications that enables businesses to effectively build, deploy, manage and personalize Internet shop space. There is a security gap between Oracle iStore Versions 12.2.5 and 12.2.14 in Oracle E-Businness Suite, which stems from the fact that uncertified assailants can attack through the HTTP network and may lead to unauthorized data access and modification.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

甲骨文

Published

2025-10-21

Last Modified

2026-02-24

References

https://www.oracle.com/security-alerts/cpuoct2025.html https://access.redhat.com/security/cve/cve-2025-53041

Patch

https://www.oracle.com/security-alerts/cpuoct2025.html

Share on: