LiveActive security incident?Get immediate response
CVE Record

CVE-2025-61882: Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publish...

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CriticalCVSS 9.8Known exploitedUpdated
Glexia's TakeHuman reviewedcritical

Security readout for executives and security teams

Plain-English summary

Oracle E-Business Suite has a critical flaw that lets an attacker on the internet take over the system without a password or any user clicking anything. Oracle issued an emergency advisory and CISA added it to the Known Exploited Vulnerabilities catalog, meaning attackers are actively using it. Any business running affected E-Business Suite versions should treat this as an urgent patching priority.

Executive priority

Treat as a top-tier emergency. This flaw is being exploited in the wild against Oracle E-Business Suite, a system commonly tied to finance and ERP operations. Authorize out-of-cycle patching, hunting, and exposure review now; delay risks data theft, fraud, and operational disruption with potential regulatory and audit consequences.

Technical view

CVE-2025-61882 is an unauthenticated remote code execution vulnerability in the BI Publisher Integration component of Oracle Concurrent Processing within Oracle E-Business Suite versions 12.2.3 through 12.2.14. CVSS 3.1 base score is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) with full confidentiality, integrity, and availability impact. CWE-287 (Improper Authentication) applies. Oracle published an out-of-cycle Security Alert addressing the issue.

Likely exposure

Internet-reachable Oracle E-Business Suite 12.2.3–12.2.14 deployments with the Concurrent Processing/BI Publisher Integration component exposed over HTTP are at highest risk. Internal-only EBS environments still face threat from any network-adjacent attacker. Many enterprises run EBS for finance, HR, and supply chain, so exposure is often broad and business-critical.

Exploitation context

Active exploitation is confirmed: CISA added CVE-2025-61882 to the Known Exploited Vulnerabilities catalog, and CrowdStrike published research identifying a campaign targeting Oracle E-Business Suite using this zero-day. Oracle issued an out-of-cycle Security Alert. The vulnerability requires no authentication and no user interaction over the network.

Researcher notes

Vulnerability sits in BI Publisher Integration within Oracle Concurrent Processing. CWE-287 plus a 9.8 CVSS and unauthenticated network vector point to an authentication-bypass leading to takeover. CrowdStrike attributes a targeted campaign exploiting this as a zero-day prior to Oracle's alert. Validate patch chain dependencies; some Oracle alerts require prerequisite CPUs. Track CISA KEV due date and Oracle advisory updates for additional affected components or workarounds.

Mitigation direction

  • Apply Oracle's Security Alert patch for CVE-2025-61882 to all EBS 12.2.3–12.2.14 environments immediately.
  • Restrict internet exposure of Oracle Concurrent Processing and BI Publisher endpoints behind VPN or allow-lists.
  • Follow Oracle's July 2025 Critical Patch Update guidance and any referenced prerequisite patches.
  • Hunt for indicators of compromise published in CrowdStrike's reporting on the EBS zero-day campaign.
  • Engage Oracle Support if patching is blocked to obtain interim vendor guidance.
  • Increase WAF and network monitoring around EBS HTTP services until patches are verified.

Validation and detection

  • Inventory all Oracle E-Business Suite instances and confirm versions against the 12.2.3–12.2.14 affected range.
  • Verify patch level against Oracle's CVE-2025-61882 Security Alert advisory after deployment.
  • Review web server, EBS Concurrent Processing, and BI Publisher logs for anomalous unauthenticated requests.
  • Check endpoint and EDR telemetry against CrowdStrike-published indicators tied to the campaign.
  • Confirm CISA KEV remediation deadline is tracked and reported in vulnerability management records.
  • Re-test external attack surface to ensure EBS HTTP services are not unintentionally exposed.
Prepared
Reviewed
Confidence
high
Sources
6

Michael Williams reviewed this cited source version on .

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-287: Credential and account abuse lookup

Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-61882 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
Yes
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
5Source links

CISA KEV status

Status
Known exploited
Source
CISA / ADP
Date added
Not provided

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2025-61882Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Oracle CorporationOracle Concurrent Processing12.2.3Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-287 · source CWE mapping

Improper Authentication

Improper Authentication represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.