CVE-2025-61884
9.5 CISA KEVOracle · E-Business Suite (Oracle Configurator)
An unauthenticated SSRF vulnerability in the Oracle Configurator component of Oracle E-Business Suite allows remote attackers to access sensitive data.
Executive summary
Oracle E-Business Suite is affected by a critical, actively exploited server-side request forgery vulnerability that permits unauthenticated attackers to exfiltrate sensitive data.
Vulnerability
This is a server-side request forgery (SSRF) flaw within the Runtime UI component of Oracle Configurator. It allows an unauthenticated attacker with network access to the target system to perform unauthorized requests, leading to the exposure of critical data.
Business impact
The exploitation of this vulnerability poses a severe risk to organizational data integrity and confidentiality. Given the CVSS score of 9.5 and confirmed active exploitation in the wild, this flaw could lead to the unauthorized retrieval of sensitive business information stored within the E-Business Suite. The inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities catalog underscores the high probability of targeted attacks, potentially resulting in significant operational and reputational damage.
Remediation
Immediate Action: Apply the vendor-provided security patches immediately as detailed in the official Oracle security alert.
Proactive Monitoring: Monitor network traffic for unusual outbound HTTP requests originating from the Oracle E-Business Suite servers, particularly those directed toward internal infrastructure or sensitive external endpoints.
Compensating Controls: Implement strict egress filtering on the network and ensure that the Oracle Configurator component is isolated behind a Web Application Firewall configured to detect and block SSRF attack patterns.
Exploitation status
Public Exploit Available: Yes, multiple public proofs-of-concept are available via GitHub.
Analyst recommendation
The active exploitation of this vulnerability in the wild, coupled with its high CVSS severity, mandates an immediate response. Security teams must prioritize the application of vendor-supplied patches and audit system logs for signs of unauthorized access. Given the risk of data exfiltration and confirmed use by malicious actors, failure to remediate this vulnerability promptly leaves the organization exposed to critical security incidents.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
Sources
- Oracle Advisory Vendor advisory