CVE-2025-53072
Published: May 21, 2026
Official Description
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Risk Analysis
This critical vulnerability in Oracle Marketing, part of Oracle E-Business Suite, allows unauthenticated attackers to fully compromise the system. The flaw is easily exploitable via network access over HTTP. Its CVSS score of 9.8 indicates severe impacts on confidentiality, integrity, and availability, making it an urgent concern.
This vulnerability is actively exploited in the wild and is listed in CISA's KEV catalog. Attackers can exploit this remotely without authentication due to the network attack vector and low attack complexity.
Apply the latest security patches and updates for Oracle E-Business Suite, specifically for Oracle Marketing component versions 12.2.3 through 12.2.14. Restrict network access to the Oracle Marketing application to trusted sources.
Technical Analysis
CVE-2025-53072 requires local access, meaning attackers must already have a foothold on the target system.
Exploitation requires some privileges, which limits the exposure to scenarios where an attacker has already gained initial access.
CISA has added CVE-2025-53072 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. U.S. federal agencies are required to patch this within the mandated timeframe, and all organizations should treat remediation as urgent.
Affected Vendors & Products
Exploit & PoC Resources
Quick Facts
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2025-53072 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts
- !CISA KEV: Federal agencies must patch per BOD 22-01 timeline
- !Active exploitation confirmed — treat as P1