Cyber Security News

Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication

Oracle has disclosed a critical vulnerability in its E-Business Suite that enables unauthenticated attackers to remotely access sensitive data, raising alarms for enterprises relying on the platform for core operations.

Tracked as CVE-2025-61884, the flaw affects the Oracle Configurator component and was detailed in a security alert released on October 11, 2025.

This comes just days after another exploited E-Business Suite vulnerability, CVE-2025-61882, highlighting ongoing security challenges in Oracle’s enterprise resource planning software.

The issue allows hackers to bypass authentication over HTTP, potentially exposing configuration data critical to business processes like finance and supply chain management.​

Oracle E-Business Suite RCE Vulnerability

CVE-2025-61884 resides in the Runtime UI of Oracle Configurator, a module used for managing product and service configurations within E-Business Suite.

Attackers with network access can exploit this flaw without credentials, leading to unauthorized data retrieval or enumeration. The vulnerability stems from an authentication bypass mechanism, though specific technical details like affected endpoints remain undisclosed to prevent widespread abuse.

Oracle rates it with a CVSS 3.1 base score of 7.5, classifying it as high severity due to its ease of exploitation. No credits are given to external researchers, suggesting internal discovery by Oracle’s security team.​

The following table summarizes key aspects of the vulnerability:

CVE IDAffected ComponentProtocolCVSS Base ScoreAttack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability ImpactSupported Versions
CVE-2025-61884Oracle Configurator (Runtime UI)HTTP7.5NetworkLowNoneNoneUnchangedHighNoneNone12.2.3-12.2.14 ​

This structured breakdown underscores the remote, unauthenticated nature of the threat, making it accessible to any internet-facing deployment.​

Successful exploitation could grant hackers complete access to all Oracle Configurator data, including sensitive business configurations that drive operational decisions.

For organizations in sectors like manufacturing or retail, this means exposure of proprietary models, pricing strategies, and customer details, potentially leading to competitive disadvantages or regulatory violations.

The high confidentiality impact without affecting integrity or availability positions it as a data exfiltration vector rather than a disruptive attack.

Given the recent exploitation of CVE-2025-61882 by ransomware groups like Cl0p, security experts warn that CVE-2025-61884 could follow suit, especially as proof-of-concepts for similar flaws circulate. Enterprises with unpatched E-Business Suite instances face elevated risks, particularly if exposed to the public internet.​

Mitigations

Oracle urges immediate application of the released patches for versions 12.2.3 through 12.2.14, available via the Security Alert program for supported releases under Premier or Extended Support.

Customers on older versions should upgrade to maintained branches, as earlier releases like 12.1.3 may also be vulnerable despite lacking testing.

Additional defenses include network segmentation to limit HTTP access to the Configurator UI and monitoring for anomalous requests.

Oracle’s advisory provides detailed patch instructions through support documents, emphasizing the Lifetime Support Policy for ongoing protection.

While no active exploitation has been confirmed for this CVE, the pattern of rapid E-Business Suite attacks demands swift action to safeguard sensitive resources.​

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran is the Co-Founder and Editor-in-Chief of CyberSecurityNews.com, specializing in vulnerability analysis, malware research, ransomware, and computer forensics.

Recent Posts

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

43 minutes ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

2 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

4 hours ago

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…

4 hours ago

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions…

4 hours ago

Salesforce Confirms that Customers’ Data Was Accessed Following the Gainsight Breach

Salesforce has issued a critical security alert identifying "unusual activity" involving Gainsight-published applications connected to…

6 hours ago