Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day
The Cl0p ransomware group has been exploiting a critical zero-day vulnerability in Oracle's E-Business Suite (EBS), specifically targeting enterprise customers through CVE-2025-61882.
The Cl0p ransomware group has been exploiting a critical zero-day vulnerability in Oracle's E-Business Suite (EBS), specifically targeting enterprise customers through CVE-2025-61882.
Critical Zero-Day Vulnerability Exposed
Oracle has confirmed the exploitation of CVE-2025-61882, a severe remote code execution vulnerability affecting the Business Intelligence Publisher (BI Publisher) Integration component of Oracle EBS.
This vulnerability has a maximum CVSS score of 9.8, indicating critical severity and the potential for complete system compromise. It impacts Oracle E-Business Suite versions 12.2.3 through 12.2.14, affecting numerous organizations globally that depend on Oracle’s integrated business application suite for essential operations such as order management, logistics, and procurement.
Cl0p is identified as a sophisticated ransomware group known for targeting zero-day vulnerabilities in enterprise file transfer and business software. The group is associated with threat actors TA505 and FIN11 and has previously exploited zero-days in platforms such as Accellion, MOVEit Transfer, GoAnywhere, and Cleo.
In this campaign, Cl0p has moved from traditional file encryption to data exfiltration and extortion tactics. Oracle customers began receiving emails on October 2, indicating that attackers had stolen sensitive information from their EBS systems.
Oracle's preliminary investigation identified multiple exploited vulnerabilities, including nine additional CVEs patched in the July 2025 Critical Patch Update. These vulnerabilities, with CVSS scores ranging from 5.4 to 8.1, affect various EBS components such as Oracle Lease and Finance Management, Mobile Field Service, and Universal Work Queue.
This vulnerability has a maximum CVSS score of 9.8, indicating critical severity and the potential for complete system compromise.
CVE Identifier Affected Component CVSS Score Impact
CVE-2025-61882 BI Publisher Integration 9.8 Remote Code Execution
CVE-2025-30743 Lease and Finance Management 8.1 High Impact
CVE-2025-30744 Mobile Field Service 8.1 High Impact
CVE-2025-50105 Universal Work Queue 8.1 High Impact
CVE-2025-50071 Applications Framework 6.4 Medium Impact
Oracle has released patches for all identified vulnerabilities. Organizations are required to apply the October 2023 CPU as a prerequisite before installing the latest security updates. Public proof-of-concept exploits for CVE-2025-61882 are now available, increasing the risk for unpatched systems.
Security experts strongly advise all Oracle EBS customers to immediately assess their exposure and apply available patches. The combination of active exploitation, public exploit code, and Cl0p's capabilities presents a significant threat to vulnerable organizations.
Based on reporting by GBHackers.
