Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication

Posted on October 13, 2025October 13, 2025 By CWS

Oracle has disclosed a vital vulnerability in its E-Enterprise Suite that permits unauthenticated attackers to remotely entry delicate information, elevating alarms for enterprises counting on the platform for core operations.

Tracked as CVE-2025-61884, the flaw impacts the Oracle Configurator part and was detailed in a safety alert launched on October 11, 2025.

This comes simply days after one other exploited E-Enterprise Suite vulnerability, CVE-2025-61882, highlighting ongoing safety challenges in Oracle’s enterprise useful resource planning software program.

The difficulty permits hackers to bypass authentication over HTTP, probably exposing configuration information vital to enterprise processes like finance and provide chain administration.​

Oracle E-Enterprise Suite RCE Vulnerability

CVE-2025-61884 resides within the Runtime UI of Oracle Configurator, a module used for managing product and repair configurations inside E-Enterprise Suite.

Attackers with community entry can exploit this flaw with out credentials, resulting in unauthorized information retrieval or enumeration. The vulnerability stems from an authentication bypass mechanism, although particular technical particulars like affected endpoints stay undisclosed to stop widespread abuse.

Oracle charges it with a CVSS 3.1 base rating of seven.5, classifying it as excessive severity as a result of its ease of exploitation. No credit are given to exterior researchers, suggesting inner discovery by Oracle’s safety group.​

The next desk summarizes key elements of the vulnerability:

CVE IDAffected ComponentProtocolCVSS Base ScoreAttack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability ImpactSupported VersionsCVE-2025-61884Oracle Configurator (Runtime UI)HTTP7.5NetworkLowNoneNoneUnchangedHighNoneNone12.2.3-12.2.14 ​

This structured breakdown underscores the distant, unauthenticated nature of the menace, making it accessible to any internet-facing deployment.​

Profitable exploitation might grant hackers full entry to all Oracle Configurator information, together with delicate enterprise configurations that drive operational selections.

For organizations in sectors like manufacturing or retail, this implies publicity of proprietary fashions, pricing methods, and buyer particulars, probably resulting in aggressive disadvantages or regulatory violations.

The excessive confidentiality affect with out affecting integrity or availability positions it as a knowledge exfiltration vector relatively than a disruptive assault.

Given the latest exploitation of CVE-2025-61882 by ransomware teams like Cl0p, safety specialists warn that CVE-2025-61884 might comply with swimsuit, particularly as proof-of-concepts for comparable flaws flow into. Enterprises with unpatched E-Enterprise Suite situations face elevated dangers, significantly if uncovered to the general public web.​

Mitigations

Oracle urges instant utility of the launched patches for variations 12.2.3 via 12.2.14, obtainable by way of the Safety Alert program for supported releases below Premier or Prolonged Assist.

Clients on older variations ought to improve to maintained branches, as earlier releases like 12.1.3 can also be weak regardless of missing testing.

Further defenses embody community segmentation to restrict HTTP entry to the Configurator UI and monitoring for anomalous requests.

Oracle’s advisory offers detailed patch directions via help paperwork, emphasizing the Lifetime Assist Coverage for ongoing safety.

Whereas no energetic exploitation has been confirmed for this CVE, the sample of fast E-Enterprise Suite assaults calls for swift motion to safeguard delicate assets.​

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Authentication, Data, EBusiness, Exposes, Hackers, Oracle, RCE, Sensitive, Suite, Vulnerability

Post navigation

Previous Post: New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
Next Post: SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups

Related Posts

New EncryptHub Campaign Leverages Brave Support Platform to Deliver Malicious Payloads via MMC Vulnerability Cyber Security News
Spring Framework Security Flaws Enable Authorization Bypass and Annotation Detection Issues Cyber Security News
Threat Actors Employ Clickfix Tactics to Deliver Malicious AppleScripts That Steal Login Credentials Cyber Security News
How to Detect Hidden Redirects and Payloads Cyber Security News
Google Chrome 0-Day Vulnerability Exploited in the Wild Cyber Security News
Why Threat Prioritization Is the Key SOC Performance Driver   Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs
  • RealBlindingEDR Tool That Permanently Turn off AV/EDR Using Kernel Callbacks
  • SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups
  • Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication
  • New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Rust-Based Malware “ChaosBot” Uses Discord Channels to Control Victims’ PCs
  • RealBlindingEDR Tool That Permanently Turn off AV/EDR Using Kernel Callbacks
  • SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups
  • Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication
  • New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News