Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication
Oracle has identified a critical vulnerability in its E-Business Suite, potentially allowing unauthorized access to sensitive data. This vulnerability, tracked as CVE-2025-61884, is found in the Oracle Configurator component and was highlighted in a…
Oracle has identified a critical vulnerability in its E-Business Suite, potentially allowing unauthorized access to sensitive data. This vulnerability, tracked as CVE-2025-61884, is found in the Oracle Configurator component and was highlighted in a security alert issued on Mon, Oct 11, 2025.
Oracle E-Business Suite RCE Vulnerability
The vulnerability, CVE-2025-61884, resides in the Runtime UI of Oracle Configurator, which is essential for managing product and service configurations. It allows attackers with network access to exploit the flaw without needing credentials, leading to unauthorized data access. The vulnerability is due to an authentication bypass mechanism, with specific technical details withheld to prevent misuse.
Oracle has assigned a CVSS 3.1 base score of 7.5 to this vulnerability, classifying it as high severity due to its exploitability. The flaw was internally discovered by Oracle's security team.
CVE ID Affected Component Protocol CVSS Base Score Attack Vector Attack Complexity Privileges Required User Interaction Scope Confidentiality Impact Integrity Impact Availability Impact Supported Versions
Oracle has identified a critical vulnerability in its E-Business Suite, potentially allowing unauthorized access to sensitive data.
CVE-2025-61884 Oracle Configurator (Runtime UI) HTTP 7.5 Network Low None None Unchanged High None None 12.2.3-12.2.14
This vulnerability poses a significant risk due to its remote and unauthenticated nature, making it a potential vector for data exfiltration.
Oracle recommends immediate application of the released patches for versions 12.2.3 through 12.2.14. These are available through the Security Alert program for supported releases under Premier or Extended Support. Organizations using older versions are advised to upgrade to supported versions.
Additional security measures include network segmentation to restrict HTTP access to the Configurator UI and monitoring for unusual activities. Oracle's advisory provides comprehensive patch instructions and emphasizes adherence to the Lifetime Support Policy for continued security.
Though no active exploitation has been confirmed for CVE-2025-61884, the prevalence of attacks on E-Business Suite necessitates prompt protective actions to secure sensitive information.
Based on reporting by Cyber Security News.
