Junglewise Threat Intelligence

CVE-2025-51624: Zone Bitaqati cross-site scripting in EBS self-service platform

CVE-2025-51624 · Severity: high · CVSS 7.6 · Published 2025-08-06

Executive brief

Zone Bitaqati, a self-service platform used to manage Oracle E-Business Suite services and employee human resources, contains a security vulnerability. An attacker with basic user access could inject malicious scripts into the system. If successful, this could allow the attacker to access sensitive employee information or interfere with business operations.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Zone Bitaqati through version 3.4.0 due to improper neutralization of input during web page generation (CWE-79). The vulnerability allows a network-based attacker with low privileges (PR:L) to execute malicious scripts. According to the CVSS vector, the attack does not require user interaction (UI:N), which is atypical for standard XSS and suggests a stored XSS variant that may be automatically executed in a specific context. Successful exploitation can lead to a high impact on confidentiality and partial impact on integrity and availability. Users are advised to contact the vendor for patch information.

Affected products

  • Zone Bitaqati EBS thru 3.4.0

Timeline

  • 2025-08-06: advisory: Initial NVD publication

References