Description
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
In plain language
AI Act nowCVE-2025-61884 is an Oracle Configurator problem in Oracle E-Business Suite that lets an attacker, without logging in, read sensitive server data over HTTP; if your business uses these supported versions, you should treat this as an active, urgent risk.
CVE-2025-61884 enables unauthenticated network access over HTTP to perform sensitive data access in Oracle Configurator (Oracle E-Business Suite Runtime UI), and it has been confirmed as used in ransomware campaigns per CISA KEV.
What to do now
- Check whether you run Oracle E-Business Suite with Oracle Configurator on versions 12.2.3 through 12.2.14.
- If you are on an affected version, prioritize removing any HTTP exposure to the Oracle Configurator Runtime UI (restrict at the network/firewall/reverse proxy level).
- Review and apply the mitigations and upgrade guidance from Oracle’s security alert for CVE-2025-61884.
- Plan an immediate upgrade to the first fixed version available for your E-Business Suite/Configurator branch, and verify the Runtime UI is no longer reachable in the same way.
- Confirm through logs and monitoring that there were no unauthorized HTTP requests to Configurator endpoints around the same timeframe as any suspicious activity, and keep watching for new attempts until the fix is in place.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
6 techniquesReferences
- CISA orders feds to patch actively exploited Oracle flaw by Saturdayen-us·BleepingComputer· Exploited Oracle E-Business Suite zero-day
- Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)en-us·Help Net Security· Exploited Oracle E-Business Suite zero-day
- Look What You Made Us Patch: 2025 Zero-Days in Reviewen-us·Mandiant· Exploited GTIG zero-day tracking UNC5221
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-61884 and every CVE in our database. Create a free account — no credit card required.
Create Free Account