Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Medium

CSRF in Oracle E-Business Suite Oracle Applications Framework Personalization

IdentifiersCVE-2025-50090CWE-352· Cross-Site Request Forgery (CSRF)

CVE-2025-50090 is an easily exploitable vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite, specifically the Personalization functionality, affecting supported versions 12.2.3 through 12.2.14. According to the provided Oracle description, a low-privileged attacker with network access via HTTP can compromise Oracle Applications Framework if a separate user interacts with attacker-controlled content or a crafted request. The vulnerability requires user interaction and results in unauthorized update, insert, or delete access to some Oracle Applications Framework-accessible data, as well as unauthorized read access to a subset of accessible data. The CVSS vector (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) and the requirement for user interaction are consistent with a cross-site request forgery class issue affecting authenticated application actions within the Personalization feature.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to perform unauthorized data manipulation operations, including update, insert, and delete actions against some data accessible through Oracle Applications Framework, and to obtain unauthorized read access to a subset of that data. Because the vulnerability has scope change, compromise of the vulnerable component may significantly affect additional products beyond Oracle Applications Framework itself. The impact is limited to confidentiality and integrity; no direct availability impact is indicated in the provided content.

Mitigation

If you can’t patch tonight, do this now.

Until patches are fully deployed, reduce exposure by limiting HTTP access to Oracle E-Business Suite administrative and user interfaces to trusted networks and users, enforcing least-privilege for application accounts, and monitoring for unexpected Personalization-related data changes or suspicious authenticated requests. Because exploitation requires user interaction by another person, user awareness measures to avoid opening untrusted links or attacker-supplied web content while authenticated to E-Business Suite may reduce risk. These are compensating controls only; vendor patching is the primary mitigation.

Remediation

Patch, then assume compromise.

Apply the Oracle patch or security update for CVE-2025-50090 provided in Oracle’s Critical Patch Update guidance for Oracle E-Business Suite. The affected supported versions are 12.2.3 through 12.2.14, and Oracle indicates patches are available via its Patch Availability Documents. Organizations should update all affected Oracle E-Business Suite deployments within that version range to the vendor-fixed level.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
OracleApplications Frameworkapplication
OracleE-Business Suiteapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware1

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.