Executive brief
Oracle E-Business Suite, a comprehensive suite of business applications for enterprise resource planning and supply chain management, contains a critical security flaw in its BI Publisher Integration component. This vulnerability allows an unauthorized person to gain full control over the Concurrent Processing system, which manages high-volume background tasks and report generation. An attacker could exploit this to access sensitive business data, disrupt operations, or compromise the entire application environment.
Technical details
An improper authentication vulnerability (CWE-287) exists in the BI Publisher Integration component of Oracle Concurrent Processing within Oracle E-Business Suite. The flaw is remotely exploitable via HTTP without any prior authentication or user interaction. A successful exploit allows a network-based attacker to fully compromise the Oracle Concurrent Processing environment, leading to a complete loss of confidentiality, integrity, and availability. This vulnerability has been observed in active exploitation in the wild and is addressed in the Oracle July 2025 Critical Patch Update.
Affected products
- Oracle E-Business Suite 12.2.3-12.2.14
- Oracle Concurrent Processing 12.2.3-12.2.14
Timeline
- 2025-07-15: patched: Addressed in Oracle July 2025 Critical Patch Update
- 2025-10-06: disclosed: Initial disclosure and NVD publication
- 2025-10-06: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-10-06: exploited: Reported as exploited in the wild by CISA and security researchers