ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

NCSC: Patch Critical Oracle EBS Bug Now

criticalVulnerability exploited in the wildimportance 60CVE-2025-61882

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-61882
Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing

CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%.

Do: Apply Oracle's released patch or mitigations for CVE-2025-61882 to affected E-Business Suite 12.2.3-12.2.14 deployments as instructed by the vendor; per CISA KEV requirements, federal agencies must follow BOD 22-01 guidance or discontinue use if mitigations are unavailable. Until patched, limit internet exposure of EBS and its BI Publisher/Concurrent Processing HTTP endpoints, and review web and application logs for unauthenticated access and signs of Cl0p-style data theft or follow-on ransomware.

9.8100% KEV ransomware
  • Oracle E-Business Suite (Oracle Concurrent Processing, BI Publisher Integration component) 12.2.3 - 12.2.14
largetens of thousands of EBS environments worldwide across an estimated ~5,000+ customer organizations (est.)
Full article365 words · extracted from infosecurity-magazine.com · click to collapse

Oracle E-Business Suite (EBS) customers have been urged to patch a critical vulnerability in the product, after reports that the notorious Clop ransomware group has exploited the bug in attacks as a zero-day.

The UK’s National Cyber Security Centre (NCSC) pointed users to an emergency security update from the US software giant published over the weekend.

It patches CVE-2025-61882, an unauthenticated remote code execution (RCE) flaw impacting Oracle EBS versions 12.2.3-12.2.14.

“CVE-2025-61882 is a vulnerability in the BI Publisher Integration component of Oracle Concurrent Processing within Oracle E-Business Suite,” explained the NCSC.

“An unauthenticated attacker can send specially crafted HTTP requests to the affected component resulting in full system compromise. No user interaction is required.”

Read more on Oracle vulnerabilities: Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member

Google’s Mandiant group said the Clop ransomware group exploited the vulnerability as a zero-day back in August, along with other software flaws patched in the July 2025 Critical Patch Update.

Clop is notorious for zero-day exploits in popular software, enabling it to steal and hold to ransom sensitive corporate data. That’s the same modus operandi that enabled it to run the massive MOVEit campaign, as well as similar attacks on Accellion and GoAnywhere customers.

Scattered Lapsus$ Hunters Leak Exploit

The need to patch is made more urgent by the fact that the infamous Scattered Lapsus$ Hunters threat groups has leaked the exploit used by the Clop gang. That means more opportunistic threat actors will likely try to launch attacks on Oracle customers.

“Given that exploitation in-the-wild may have occurred since August 2025, customers of affected Oracle E-Business Suite instances that are accessible via the internet, should conduct suitable threat hunting to detect any potential malicious activity,” urged Rapid7.

The UK’s NCSC has the following advice:

  • Perform a compromise assessment using IoCs published in Oracle’s advisory
  • Contact Oracle’s PSIRT and the NCSC if you suspect compromise
  • Install the latest Oracle E-Business Suite (EBS) update. The October 2023 Critical Patch Update must be installed first
  • Minimize the number of software instances directly accessible from the public internet. Where Oracle EBS needs to be exposed to the internet, follow Oracle’s deployment guidelines 

Image credit: JasonDoiy / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ncsc-patch-critical-oracle-ebs-bug/