Washington Post notifies 10,000 individuals affected in Oracle
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-61884 | Unauthenticated SSRF in Oracle E-Business Suite Configurator Oracle Configurator, a component of Oracle E-Business Suite, is affected by a server-side request forgery (SSRF) flaw in its Runtime UI component (CVE-2025-61884). The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can trigger the server to make attacker-controlled requests, compromising Oracle Configurator and gaining unauthorized access to critical data or complete access to all data accessible to Oracle Configurator. The CVSS 3.1 score is 7.5 (high) with confidentiality-only impact, meaning the flaw primarily exposes sensitive data rather than altering or destroying it. All supported Oracle E-Business Suite 12.2.x releases from 12.2.3 through 12.2.14 are affected, and Oracle has issued an emergency security update in response. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20 with known ransomware use, and EPSS assigns a 97.8% probability of exploitation in the next 30 days (100th percentile). Do: Apply the fixes from Oracle's emergency security update for CVE-2025-61884 across all E-Business Suite 12.2.3-12.2.14 environments, prioritizing internet-exposed instances; U.S. federal agencies must remediate per BOD 22-01 or follow applicable cloud-service guidance by the KEV due date. Until patched, restrict untrusted network access to the Configurator Runtime UI (HTTP) and monitor EBS logs and outbound server-side requests for signs of exploitation. Given the confirmed ransomware association, hunt for follow-on activity such as unusual data access or lateral movement originating from EBS servers. | 7.5 | 96% | KEV ransomware PoC |
| largetens of thousands of enterprise deployments overall; several thousand Oracle E-Business Suite instances exposed to the internet |
Full article410 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 14, 2025

The Washington Post alerts nearly 10,000 employees and contractors that personal and financial data was exposed in the Oracle breach.
The Washington Post warns nearly 10,000 staff and contractors that personal and financial data was exposed in the Oracle breach. The popular newspaper has approximately 2.5M digital subscribers.
Between July 10 and August 22, threat actors exploited a then-zero-day Oracle E-Business Suite flaw, tracked as CVE-2025-61884, to access parts of the Washington Post network, stealing sensitive data. In late September, the Clop ransomware group attempted extortion.
On September 29, 2025, the Washington Post was alerted by a threat actor claiming access to its Oracle E-Business Suite. An investigation, aided by experts, confirmed a widespread, previously unknown Oracle vulnerability affecting many customers.
In mid-October, the Clop Ransomware group claimed the breach of The Washington Post and added the American daily newspaper to its Tor data leak site.
The group claimed the company was breached due to its neglect of security, despite its responsibility to protect customers.
“The Post’s investigation confirmed that it was impacted by this exploit and determined that, between July 10, 2025, and August 22, 2025, certain data was accessed and acquired without authorization. Upon learning this, the Post conducted a prompt review of the impacted data in order to determine what information was affected and identify contact information for affected individuals.” reads the data breach notification sent to the impacted individuals and shared with Maine Attorney General. “On October 27, 2025, the Post confirmed that certain personal information belonging to current and former employees and contractors was affected by this incident.”
The stolen data varies by individual; however, it may include names, bank account numbers and associated routing numbers, Social Security numbers, and/or tax ID numbers.
The company provides affected individuals with 12 months of free identity protection and advises them to freeze their credit files and enable fraud alerts.
Harvard and Envoy Air are among the confirmed victims of the Oracle E-Business Suite breach.
“Twenty-nine alleged victims of the Oracle EBS hack have been listed on the Cl0p leak website to date. The organizations that were the first to be named, such as Harvard University, South Africa’s Wits University, and American Airlines subsidiary Envoy Air, confirmed being impacted shortly after they were named by the attackers in mid-October.” reported SecurityWeek.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, The Washington Post)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184596/data-breach/washington-post-notifies-10000-individuals-affected-in-oracle-linked-data-theft.html