CVE-2025-30702

Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.3-19.26. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and amp; Provisioning. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Fleet Patching and amp; Provisioning accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:fleet_patching_and_provisioning:*:*:*:*:*:*:*:*

History

26 Jun 2025, 19:14

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:fleet_patching_and_provisioning:*:*:*:*:*:*:*:*
References () https://www.oracle.com/security-alerts/cpuapr2025.html - () https://www.oracle.com/security-alerts/cpuapr2025.html - Vendor Advisory
First Time Oracle
Oracle fleet Patching And Provisioning

17 Apr 2025, 18:15

Type Values Removed Values Added
CWE CWE-200

16 Apr 2025, 13:25

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad en el componente Fleet Patching and Provisioning de Oracle Database Server. Las versiones compatibles afectadas son la 19.3-19.26. Esta vulnerabilidad, fácilmente explotable, permite a un atacante no autenticado con acceso a la red vía HTTP comprometer Fleet Patching and Provisioning. Los ataques exitosos de esta vulnerabilidad pueden resultar en acceso de lectura no autorizado a un subconjunto de datos accesibles de Fleet Patching and Provisioning. Puntuación base de CVSS 3.1: 5.3 (Afecta a la confidencialidad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

15 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 21:15

Updated : 2025-06-26 19:14


NVD link : CVE-2025-30702

Mitre link : CVE-2025-30702

CVE.ORG link : CVE-2025-30702


JSON object : View

Products Affected

oracle

  • fleet_patching_and_provisioning
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor