Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild
## Cybersecurity: Oracle E-Business Suite Vulnerability
Cybersecurity: Oracle E-Business Suite Vulnerability
Oracle has released an emergency security alert addressing a critical zero-day vulnerability, identified as CVE-2025-61882 , within its E-Business Suite. This vulnerability is currently being exploited by the Cl0p ransomware group.
The vulnerability affects the Business Intelligence Publisher (BI Publisher) Integration component and has a CVSS score of 9.8, indicating critical severity. It allows for remote code execution without the need for authentication.
The affected Oracle EBS versions range from 12.2.3 to 12.2.14. Organizations need to implement Oracle's October 2023 Critical Patch Update (CPU) before applying the latest security patches to mitigate this issue.
The Cl0p ransomware group has been targeting Oracle E-Business Suite installations, using this zero-day vulnerability to access enterprise systems unlawfully. Public proof-of-concept exploits are now available, increasing the risk for unpatched systems.
Oracle’s security advisory includes indicators of compromise (IOCs) to assist organizations in detecting intrusions. Patches addressing CVE-2025-61882 and additional vulnerabilities from the July 2025 Critical Patch Update have been released.
Oracle has released an emergency security alert addressing a critical zero-day vulnerability, identified as CVE-2025-61882 , within its E-Business Suite.
It is crucial for security teams to prioritize immediate patching of affected Oracle EBS systems. Network monitoring for suspicious activity and reviewing access logs for unauthorized actions are recommended measures.
Risk Factors Details
Affected Products Oracle E-Business Suite, BI Publisher Integration 12.2.3 through 12.2.14
Impact Remote Code Execution
Exploit Prerequisites Network access to Oracle EBS instance, No authentication required
CVSS 3.1 Score 9.8 (Critical)
Maintaining current patch levels and implementing defense-in-depth strategies are essential to protect against zero-day exploitation campaigns.
Based on reporting by Cyber Security News.
