Harvard says ‘limited number of parties’ impacted by breach linked to Oracle zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-61882 | Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%. Do: Apply Oracle's released patch or mitigations for CVE-2025-61882 to affected E-Business Suite 12.2.3-12.2.14 deployments as instructed by the vendor; per CISA KEV requirements, federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable. Until patched, limit internet exposure of EBS and its BI Publisher/Concurrent Processing HTTP endpoints, and review web and application logs for unauthenticated access and signs of Cl0p-style data theft or follow-on ransomware. | 9.8 | 100% | KEV ransomware |
| largetens of thousands of EBS environments worldwide across an estimated ~5,000+ customer organizations (est.) | |
| CVE-2025-61884 | Unauthenticated SSRF in Oracle E-Business Suite Configurator Oracle Configurator, a component of Oracle E-Business Suite, is affected by a server-side request forgery (SSRF) flaw in its Runtime UI component (CVE-2025-61884). The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can trigger the server to make attacker-controlled requests, compromising Oracle Configurator and gaining unauthorized access to critical data or complete access to all data accessible to Oracle Configurator. The CVSS 3.1 score is 7.5 (high) with confidentiality-only impact, meaning the flaw primarily exposes sensitive data rather than altering or destroying it. All supported Oracle E-Business Suite 12.2.x releases from 12.2.3 through 12.2.14 are affected, and Oracle has issued an emergency security update in response. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20 with known ransomware use, and EPSS assigns a 97.8% probability of exploitation in the next 30 days (100th percentile). Do: Apply the fixes from Oracle's emergency security update for CVE-2025-61884 across all E-Business Suite 12.2.3-12.2.14 environments, prioritizing internet-exposed instances; U.S. federal agencies must remediate per BOD 22-01 or follow applicable cloud-service guidance by the KEV due date. Until patched, restrict untrusted network access to the Configurator Runtime UI (HTTP) and monitor EBS logs and outbound server-side requests for signs of exploitation. Given the confirmed ransomware association, hunt for follow-on activity such as unusual data access or lateral movement originating from EBS servers. | 7.5 | 96% | KEV ransomware PoC |
| largetens of thousands of enterprise deployments overall; several thousand Oracle E-Business Suite instances exposed to the internet |
Full article558 words · extracted from therecord.media · click to collapse
Harvard University confirmed that it was impacted by a recent campaign that exploited a vulnerability involving Oracle’s E-Business Suite (EBS) system. In a statement to Recorded Future News, the university said it is investigating recent claims from hackers that data was stolen from the system. Officials confirmed that the incident “impacts a limited number of parties associated with a small administrative unit.” “Harvard is aware of reports that data associated with the University has been obtained as a result of a zero-day vulnerability in the Oracle E-Business Suite system. This issue has impacted many Oracle E-Business Suite customers and is not specific to Harvard,” a university spokesperson said. “Upon receiving it from Oracle, we applied a patch to remediate the vulnerability. We are continuing to monitor and have no evidence of compromise to other University systems.” On Saturday, Harvard University was listed on the leak site of a Russian ransomware gang known as Clop, which has claimed for weeks that it stole troves of data through vulnerabilities in the Oracle E-Business Suite — a popular business platform containing several applications that manage finance, human resources and supply chain functions. The FBI and cybersecurity officials in the U.K. confirmed reports from Google-owned security firm Mandiant that the campaign was tied to exploitation of the vulnerability tracked as CVE-2025-61882. FBI Assistant Director Brett Leatherman said CVE-2025-61882 is a “‘stop-what-you’re-doing and patch immediately’ vulnerability.” This weekend, Oracle released a new advisory warning customers of another vulnerability, CVE-2025-61884, impacting the Oracle E-Business Suite. The campaign against the E-Business Suite began two weeks ago when threat actors claiming to be tied to Clop attempted to extort corporate executives by threatening to leak sensitive information they claim was stolen through the platform. Oracle confirmed the campaign but initially said the hackers were exploiting bugs that had been addressed in a July update, without specifying which vulnerabilities were being used. Austin Larsen, principal threat analyst at Google Threat Intelligence Group, said they are aware of dozens of victims, but “expect there are many more.” “Based on the scale of previous CL0P campaigns, it is likely there are over a hundred," he said. Mandiant said last week that the hackers likely chained together multiple distinct vulnerabilities, including CVE-2025-61882, to gain access to the platform and “steal mass amounts of customer data.” The FBI’s Leatherman said that Oracle E-Business Suite customers should isolate potentially affected servers and monitor threat intelligence channels because “exploit activity could escalate quickly.” “Oracle EBS remains a backbone ERP system for major enterprises and public-sector environments, which means attackers have every incentive to weaponize this one fast,” he explained. “If you suspect compromise - please connect with us.” Cynthia Kaiser, former Deputy Director of the FBI’s Cyber Division who now works for incident response firm Halcyon, said the first observed email contact from Clop began in late September. “We have seen seven and eight figure demands thus far,” Kaiser said of Clop’s ransom demands, adding that the hackers shared screenshots and filetree listings to prove they had accessed data.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/harvard-says-limited-number-linked-to-data-theft