ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Another remotely exploitable Oracle EBS vulnerability requires your attention (CVE-2025-61884)

criticalVulnerability exploited in the wildimportance 60CVE-2025-61884CVE-2025-61882

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-61882
Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing

CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%.

Do: Apply Oracle's released patch or mitigations for CVE-2025-61882 to affected E-Business Suite 12.2.3-12.2.14 deployments as instructed by the vendor; per CISA KEV requirements, federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable. Until patched, limit internet exposure of EBS and its BI Publisher/Concurrent Processing HTTP endpoints, and review web and application logs for unauthenticated access and signs of Cl0p-style data theft or follow-on ransomware.

9.8100% KEV ransomware
  • Oracle E-Business Suite (Oracle Concurrent Processing, BI Publisher Integration component) 12.2.3 - 12.2.14
largetens of thousands of EBS environments worldwide across an estimated ~5,000+ customer organizations (est.)
CVE-2025-61884
Unauthenticated SSRF in Oracle E-Business Suite Configurator

Oracle Configurator, a component of Oracle E-Business Suite, is affected by a server-side request forgery (SSRF) flaw in its Runtime UI component (CVE-2025-61884). The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can trigger the server to make attacker-controlled requests, compromising Oracle Configurator and gaining unauthorized access to critical data or complete access to all data accessible to Oracle Configurator. The CVSS 3.1 score is 7.5 (high) with confidentiality-only impact, meaning the flaw primarily exposes sensitive data rather than altering or destroying it. All supported Oracle E-Business Suite 12.2.x releases from 12.2.3 through 12.2.14 are affected, and Oracle has issued an emergency security update in response. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20 with known ransomware use, and EPSS assigns a 97.8% probability of exploitation in the next 30 days (100th percentile).

Do: Apply the fixes from Oracle's emergency security update for CVE-2025-61884 across all E-Business Suite 12.2.3-12.2.14 environments, prioritizing internet-exposed instances; U.S. federal agencies must remediate per BOD 22-01 or follow applicable cloud-service guidance by the KEV due date. Until patched, restrict untrusted network access to the Configurator Runtime UI (HTTP) and monitor EBS logs and outbound server-side requests for signs of exploitation. Given the confirmed ransomware association, hunt for follow-on activity such as unusual data access or lateral movement originating from EBS servers.

7.596% KEV ransomware PoC
  • Oracle E-Business Suite - Oracle Configurator (Runtime UI component) 12.2.3 through 12.2.14
largetens of thousands of enterprise deployments overall; several thousand Oracle E-Business Suite instances exposed to the internet
Full article420 words · extracted from helpnetsecurity.com · click to collapse

Oracle has revealed the existence of yet another remotely exploitable Oracle E-Business Suite vulnerability (CVE-2025-61884).

Oracle EBS vulnerability CVE-2025-61884

About CVE-2025-61884

CVE-2025-61884 is a vulnerability in the Runtime user interface in the Oracle Configurator product of Oracle E-Business Suite (EBS).

Like CVE-2025-61882 before it, it officially affects the ESB versions 12.2.3 through 12.2.14.

According to the NIST national vulnerability database entry for CVE-2025-61884, this is an “easily exploitable vulnerability [that] allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.”

Oracle Security’s CIS Rob Duhart says that the vulnerability “may allow access to sensitive resources” and “affects some deployments of Oracle E-Business Suite.”

The company “strongly recommends” that customers apply the updates or mitigations provided.

But, as an Oracle customer already noted, at least one earlier version (12.1.3) has been confirmed to be also vulnerable, and other changes to the patch availability document might be made in the coming days.

Oracle does not say whether CVE-2025-61884 is under active attack or has been exploited as a zero-day, possibly by the same attackers who stole data of Oracle EBS customers via CVE-2025-61882 and are now extorting them.

With exploit scripts for CVE-2025-61882 having been leaked, security researchers expect further attacks.

We’ve reached out to Oracle for more information on CVE-2025-61884, and we’ll update this article if we hear back from them.

UPDATE (October 15, 2025, 07:30 a.m. ET):

Oracle has declined to answer our questions and pointed us towards the advisory.

But with CVE-2025-61884’s description noting the flaw is in the Oracle Configurator product of Oracle EBS and watchTowr’s analysis of a leaked exploit showing that it targets the /OA_HTML/configurator/UiServlet endpoint, it looks like CVE-2025-61884 – and not the previously exploited and then patched CVE-2025-61882 – might be leveraged by that particular exploit.

UPDATE (October 16, 2025, 01:00 p.m. ET):

“Mandiant and GTIG have observed evidence that both the ‘UiServlet’ and ‘SyncServlet’-related exploit chains have been exploited in the wild as a zero day,” Zander Work, Senior Security Engineer at Google Threat Intelligence Group, told Help Net Security.

“At this time, we are not able to attribute any specific exploitation activity to a specific actor, but it’s likely that at least some of the exploitation activity we observed was conducted by actors now conducting Cl0p-branded extortion operations.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/10/12/another-remotely-exploitable-oracle-ebs-vulnerability-requires-your-attention-cve-2025-61884/