SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-61884

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

KEVHIGH 7.5EPSS 95.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 November 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
95.89% probability · 100th percentile
CISA KEV
Listed 20 October 2025 · due 10 November 2025 · used in ransomware campaigns
Weakness
CWE-22, CWE-93, CWE-287, CWE-444, CWE-501, CWE-918
Affected
oracle/configurator
Source
secalert_us@oracle.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.