
CVE-2025-30710
https://notcve.org/view.php?id=CVE-2025-30710
15 Apr 2025 — Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availabili... • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-284: Improper Access Control •

CVE-2025-30709
https://notcve.org/view.php?id=CVE-2025-30709
15 Apr 2025 — Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (... • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-284: Improper Access Control •

CVE-2025-30708
https://notcve.org/view.php?id=CVE-2025-30708
15 Apr 2025 — Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions that are affected are 12.2.4-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle User Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impac... • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2025-30707
https://notcve.org/view.php?id=CVE-2025-30707
15 Apr 2025 — Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-284: Improper Access Control •

CVE-2025-30706
https://notcve.org/view.php?id=CVE-2025-30706
15 Apr 2025 — Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-276: Incorrect Default Permissions •

CVE-2025-30705
https://notcve.org/view.php?id=CVE-2025-30705
15 Apr 2025 — Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-400: Uncontrolled Resource Consumption •

CVE-2025-30704
https://notcve.org/view.php?id=CVE-2025-30704
15 Apr 2025 — Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availabili... • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-400: Uncontrolled Resource Consumption •

CVE-2025-30703
https://notcve.org/view.php?id=CVE-2025-30703
15 Apr 2025 — Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-863: Incorrect Authorization •

CVE-2025-30701
https://notcve.org/view.php?id=CVE-2025-30701
15 Apr 2025 — Vulnerability in the RAS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via Oracle Net to compromise RAS Security. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical... • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-276: Incorrect Default Permissions •

CVE-2025-30699 – Ubuntu Security Notice USN-7479-1
https://notcve.org/view.php?id=CVE-2025-30699
15 Apr 2025 — Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability im... • https://www.oracle.com/security-alerts/cpuapr2025.html • CWE-284: Improper Access Control •