Oracle E-Business Suite zero-day under attack
Oracle's E-Business Suite, a financial management tool used by businesses, has a critical flaw attackers are actively exploiting. This lets them take control of affected systems without warning.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Affects
- Oracle E-Business Suite
- Exploited
- Not confirmedNo confirmation recorded
How it works
Attackers send specially crafted requests to the Oracle E-Business Suite's financial reporting module, tricking it into running unauthorized code on the server.
What to do
Check whether the installed Oracle E-Business Suite version is older than the fixed version in the vendor advisory or current release.
Update version 12.2.13.3 or immediately to the current version using Oracle's official update tools. No workaround exists.
Technical details
Affected software: Oracle E-Business Suite
CVE-2025-61882 affects the BI Publisher Integration component of Oracle Concurrent Processing within E-Business Suite, outdated versions. It carries a outdated CVSS versions score of the latest version (critical): an unauthenticated attacker with only network access over HTTP can fully compromise the component, with high impact to confidentiality, integrity, and availability. CISA added it to its Known Exploited Vulnerabilities catalog after confirming active exploitation, and the Clop group has used it in a data-theft extortion campaign, reusing infrastructure previously tied to its 2023 MOVEit (CVE-2023-34362) attacks.