Oracle has disclosed a critical security vulnerability, CVE-2025-61884, affecting the Oracle Configurator component within Oracle E-Business Suite (EBS) versions 12.2.3 through 12.2.14. This vulnerability resides in the Runtime user interface of Oracle Configurator and allows unauthenticated attackers with network access via HTTP to remotely exploit the system. Successful exploitation can result in unauthorized access to sensitive configuration data or potentially complete access to all data accessible through Oracle Configurator. The flaw is classified as easily exploitable, requiring no user interaction or authentication, which significantly increases the risk profile for organizations relying on Oracle EBS for critical business operations. The National Vulnerability Database has assigned a CVSS 3.1 base score of 7.5 to CVE-2025-61884, indicating its high severity and the potential for significant impact on enterprise confidentiality and integrity. Oracle Security’s CIS Rob Duhart has emphasized that the vulnerability may allow access to sensitive resources and could affect a wide range of EBS deployments. While Oracle has not confirmed whether this vulnerability is currently being exploited in the wild, there is heightened concern due to recent incidents involving similar vulnerabilities, such as CVE-2025-61882, which was exploited to steal data from Oracle EBS customers. Security researchers warn that the public availability of exploit scripts for related vulnerabilities increases the likelihood of imminent attacks targeting CVE-2025-61884. Oracle has issued patches and strongly recommends that all affected customers apply the updates or mitigations immediately to protect their systems. There are also reports that earlier versions, such as 12.1.3, may be vulnerable, and Oracle may update its patch documentation as more information becomes available. The vulnerability’s ability to bypass authentication controls and grant attackers access to critical business configuration data poses a direct threat to organizations’ operational security. Oracle EBS is integral to business workflows in sectors such as manufacturing, finance, and supply chain management, making the potential impact of this vulnerability especially severe. Organizations are advised to review Oracle’s security advisories, apply the recommended patches without delay, and monitor for further updates as the situation evolves. The exposure of sensitive configuration data could lead to broader compromises, including data theft, business disruption, and regulatory consequences. Security teams should also assess their current EBS deployments for signs of compromise and ensure that all network access to Oracle Configurator is tightly controlled. The urgency of this vulnerability is underscored by the potential for attackers to exploit it with minimal effort, making rapid remediation essential for all Oracle EBS customers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Coverage of Oracle's emergency response said the latest E-Business Suite patch came as fallout tied to Clop-related activity widened, indicating broader concern around exploitation pressure and impact. This represented an escalation in the narrative beyond the initial disclosure of the flaw alone.
Oracle issued an out-of-band emergency patch for CVE-2025-61884 in Oracle E-Business Suite. Reports characterized it as Oracle's second emergency E-Business Suite patch within two weeks.
Oracle warned of a critical remotely exploitable vulnerability in Oracle E-Business Suite, tracked as CVE-2025-61884, that could allow unauthenticated access to sensitive data. Multiple reports describe the flaw as affecting internet-exposed EBS environments and requiring urgent attention.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcecsoonline.com
Open sourcesecurityonline.info
Open sourcetechrepublic.com
Open sourcethehackernews.com
Open sourcethecyberthrone.in
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.