CVE-2025-61884
Summary
| CVE | CVE-2025-61884 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-12 03:15:34 UTC |
| Updated | 2026-08-04 05:16:36 UTC |
| Description | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.977880000 probability, percentile 0.998990000 (date 2026-08-04)
CISA KEV: Listed on 2025-10-20; due 2025-11-10; ransomware use Known
Problem Types: CWE-22 | CWE-93 | CWE-287 | CWE-444 | CWE-501 | CWE-918 | Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. | CWE-918 CWE-918 Server-Side Request Forgery (SSRF) | CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CWE-93 CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') | CWE-444 CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | CWE-287 CWE-287 Improper Authentication | CWE-501 CWE-501 Trust Boundary Violation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA Known Exploited Vulnerability
| Vendor | Oracle |
|---|---|
| Product | E-Business Suite |
| Name | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Configurator | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Oracle Corporation | Oracle Configurator | affected 12.2.3 12.2.14 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| blogs.oracle.com/security/post/apply-july-2025-cpu | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | blogs.oracle.com | Vendor Advisory |
| www.oracle.com/security-alerts/alert-cve-2025-61884.html | [email protected] | www.oracle.com | Vendor Advisory |
| labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-au... | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | labs.watchtowr.com | Exploit, Press/Media Coverage |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2025-10-20T00:00:00.000Z | CVE-2025-61884 added to CISA KEV |