PT-2025-40791 · Oracle · Oracle E-Business Suite +1

Inkmoro

+3

·

Published

2025-10-04

·

Updated

2025-11-21

·

CVE-2025-61882

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle E-Business Suite versions 12.2.3 through 12.2.14
Description Oracle E-Business Suite is affected by a critical remote code execution (RCE) vulnerability (CVE-2025-61882). This flaw allows unauthenticated attackers to execute arbitrary code, potentially leading to full system compromise and data theft. The vulnerability is actively exploited by the Cl0p ransomware group. Exploitation involves bypassing authentication through the BI Publisher Integration component, utilizing SSRF, CRLF injection, and XSLT template manipulation. A public proof-of-concept exploit is available. Multiple organizations have been impacted, with reports of data exfiltration and extortion attempts. Indicators of compromise (IOCs) have been shared by security researchers.
Recommendations Oracle E-Business Suite versions 12.2.3 through 12.2.14: Apply the security patch released by Oracle immediately.

Exploit

Fix

DoS

RCE

SSRF

Improper Authentication

HTTP Request/Response Smuggling

Improper Authorization

Path traversal

XXE

Improper Access Control

Related Identifiers

BDU:2025-12468
BDU:2025-12935
CVE-2025-61882

Affected Products

Bi Publisher
Oracle E-Business Suite