🔴 CVE-2025-61882

Critical unauthenticated remote code execution vulnerability in Oracle E-Business Suite Concurrent Processing component accessible via HTTP. Actively exploited by Cl0p ransomware group for data theft attacks with complete system takeover potential.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
Yes (+131d)
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-10-05

Added to CISA KEV: 2025-10-06 1 DAY BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2025-10-06)

CVE-2025-61882 is a critical vulnerability affecting Oracle E-Business Suite (EBS), particularly the Concurrent Processing component's BI Publisher Integration [3][1]. Here's what is known about its exploitation:

  • Affected Applications: The vulnerability affects the Oracle Concurrent Processing product of Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.14 [3][8].
  • Internet-Facing Applications/Services: It is remotely exploitable over HTTP without authentication, meaning it can be exploited over a network without needing a username or password [7][1].
  • Active Exploitation: There is evidence of active exploitation in the wild. Oracle released an emergency fix for this vulnerability after it was exploited by the Cl0p ransomware group in data theft attacks [12][4].
  • Attack Vectors/Exploitation Methods: The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing and execute arbitrary code [1][6].
  • Targeted Attacks: Cl0p ransomware group has exploited this vulnerability in data theft attacks [10][11]. They stole large amounts of data from several victims in August 2025 by exploiting multiple vulnerabilities in Oracle EBS, including CVE-2025-61882 [5].
  • CISA KEV Status: While not explicitly stated in the provided context as being added to the CISA Known Exploited Vulnerabilities (KEV) catalog, the active exploitation by a known ransomware group would likely lead to its inclusion or consideration for inclusion in the KEV [2].
  • Technical Details: CVE-2025-61882 has a CVSS score of 9.8, indicating a critical vulnerability [1][9]. It is an RCE (Remote Code Execution) vulnerability in the BI Publisher Integration component of Oracle’s Concurrent Processing module [1]. It is easily exploitable, allowing unauthenticated attackers with network access via HTTP to compromise the system [3][6].

Sources

  1. CVE-2025-61882: Oracle E-Business Suite Exploited - socradar.io

    What is CVE-2025-61882? CVE-2025-61882 (CVSS 9.8) is a Remote Code Execution (RCE) vulnerability in the BI Publisher Integration component of Oracle’s Concurrent Processing module – an integral service within Oracle E-Business Suite that handles automated and background processes. This flaw is remot…

  2. Ivanti Flaw CVE-2025-0282 Actively Exploited, Impacts Connect...

    Ivanti's CVE-2025-0282 flaw, exploited by China-linked actors, enables remote code execution.In light of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-0282 to the Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to a…

  3. CVE-2025-61882 - Exploits & Severity - Feedly

    Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Conc…

  4. Latest Oracle E-Business Suite news

    Oracle is warning about a critical E-Business Suite zero-day vulnerability tracked as CVE-2025-61882 that allows attackers to perform unauthenticated remote code execution, with the flaw actively exploited in Clop data theft attacks.Oracle has linked an ongoing extortion campaign claimed by the Clop…

  5. Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp...

    The vulnerability, tracked as CVE-2025-61882 (CVSS score: 9.8), concerns an unspecified bug that could allow an unauthenticated attacker with network ...