Junglewise Threat Intelligence

CVE-2025-61884: Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected a

CVE-2025-61884 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2025-10-12

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite, a comprehensive suite of business applications for enterprise resource planning, contains a security flaw in its Configurator component. This vulnerability allows an unauthorized person to trick the server into making internal requests, potentially leading to the theft of sensitive business data. This issue is particularly serious as it is reportedly being exploited in the wild and does not require a username or password to execute.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Runtime UI component of Oracle Configurator within Oracle E-Business Suite versions 12.2.3 through 12.2.14. The flaw allows an unauthenticated remote attacker to send crafted HTTP requests to the server, which the server then executes on the attacker's behalf. This can be used to bypass network segmentation, access internal-only services, or extract sensitive data accessible to the application server. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Oracle has released patches as part of the July 2025 Critical Patch Update.

Affected products

  • Oracle Configurator 12.2.3-12.2.14

Timeline

  • 2025-10-11: disclosed: Initial disclosure by Oracle
  • 2025-10-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats