Oracle Issues High-Severity Security Alert for E-Business Suite Vulnerability

Oracle Issues High-Severity Security Alert for E-Business Suite Vulnerability

Oracle on Saturday issued a security alert warning of a newly discovered flaw in its E-Business Suite (EBS) that could allow unauthorized access to sensitive data. The vulnerability, tracked as CVE-2025-61884, carries a CVSS score of 7.5, indicating high severity, and affects versions 12.2.3 through 12.2.14 of the software.

“Easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Configurator,” according to a description in the National Institute of Standards and Technology’s (NIST) National Vulnerability Database (NVD). “Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.”

Oracle emphasized that the flaw is remotely exploitable without requiring authentication, making prompt patching essential. In its alert, the company urged users to apply updates immediately but did not indicate any confirmed exploitation in the wild. Oracle Chief Security Officer Rob Duhart noted that the vulnerability impacts “some deployments” of E-Business Suite and could be weaponized to gain access to sensitive resources.

The alert follows recent disclosures by Google Threat Intelligence Group (GTIG) and cybersecurity firm Mandiant, which reported that dozens of organizations might have been affected by the zero-day exploitation of CVE-2025-61882, another EBS vulnerability. Attackers leveraged that flaw to execute two distinct payload chains, deploying malware families such as GOLDVEIN.JAVA, SAGEGIFT, SAGELEAF, and SAGEWAVE.

While Oracle has not attributed CVE-2025-61884 exploitation to any specific threat actor, cybersecurity experts suspect involvement by a group linked to the Cl0p ransomware organization. The combination of high severity, remote exploitability, and the potential for critical data compromise underscores the urgency for organizations to review their E-Business Suite installations and apply patches without delay.

With E-Business Suite widely used in enterprise environments, the vulnerability represents a significant risk to sensitive business operations. Analysts emphasize that organizations should not only patch affected systems but also monitor for unusual activity indicative of attempted exploitation, particularly in the wake of previous zero-day attacks targeting the platform.

- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

error: Content is protected !!

Share your details to download the Cybersecurity Report 2025

Share your details to download the CISO Handbook 2025

Sign Up for CXO Digital Pulse Newsletters

Share your details to download the Research Report

Share your details to download the Coffee Table Book

Share your details to download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch