Oracle E-Business Suite Unspecified Vulnerability
Oracle Corporation — Oracle Concurrent Processing
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
9.8
99.7%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Oct 5, 2025
- Modified
- Aug 4, 2026
- Added to KEV
- Oct 6, 2025
- Federal patch due
- Oct 27, 2025
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2025-61882, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882★ 55
updated Jul 30, 2026
- rxerium/CVE-2025-61882-CVE-2025-61884★ 35
Detection for CVE-2025-61882 & CVE-2025-61884
updated Jul 13, 2026
- zerozenxlabs/CVE-2025-61882-Oracle-EBS★ 19
updated Jul 8, 2026
- AdityaBhatt3010/CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit★ 12
A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full control over vulnerable servers via malicious HTTP requests - now actively exploited in the wild.
updated May 4, 2026
- Sachinart/CVE-2025-61882★ 11
Exploit for CVE-2025-61882 (do not use without any written permission).
updated Jun 29, 2026
- BattalionX/http-oracle-ebs-cve-2025-61882.nse★ 2
Detects Oracle E-Business Suite (CVE-2025-61882). Detection: multi-tier checks — fingerprinting, version checks, endpoint & SSRF tests, timing analysis & controlled exploitation 4 high-confidence results. Default = safe fingerprinting only. Set aggressive=true 2 enable active/probing checks use w/caution. Provided By BattalionX BattalionX@proton.me
updated Oct 28, 2025
- George0Papasotiriou/CVE-2025-61882-Oracle-BI-Publisher-RCE★ 1
updated Feb 10, 2026
- 222dff-afk/Blackash-CVE-2025-61882★ 0
CVE-2025-61882
updated Oct 17, 2025
References
Frequently asked questions
What is CVE-2025-61882?
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
How severe is CVE-2025-61882?
CVE-2025-61882 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2025-61882 actively exploited in the wild?
Yes. CVE-2025-61882 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Oct 6, 2025, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2025-61882?
99.7% - meaning FIRST.org's EPSS model estimates a 99.7% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2025-61882?
Yes - a public Nuclei template referencing CVE-2025-61882 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2025-61882?
CVE-2025-61882 is classified under CWE-287 (CWE-287 Improper Authentication).
Cross-checked against
Impactr finds and proves whether CVE-2025-61882 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist