PT-2025-40791 · Oracle · Bi Publisher+1
Inkmoro
+3
·
Published
2025-10-04
·
Updated
2026-03-10
·
CVE-2025-61882
CVSS v3.1
9.8
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle E-Business Suite versions 12.2.3 through 12.2.14
Description
Oracle E-Business Suite is affected by a critical remote code execution (RCE) vulnerability (CVE-2025-61882). This flaw allows unauthenticated attackers to execute arbitrary code, potentially leading to full system compromise and data theft. The vulnerability is actively exploited by the Cl0p ransomware group. Exploitation involves bypassing authentication through the BI Publisher Integration component, utilizing SSRF, CRLF injection, and XSLT template manipulation. A public proof-of-concept exploit is available. Multiple organizations have been impacted, with reports of data exfiltration and extortion attempts. Indicators of compromise (IOCs) have been shared by security researchers.
Recommendations
Oracle E-Business Suite versions 12.2.3 through 12.2.14: Apply the security patch released by Oracle immediately.
Exploit
Fix
RCE
DoS
SSRF
Improper Authentication
Improper Access Control
XXE
Improper Authorization
Path traversal
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bi Publisher
Oracle E-Business Suite