All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2025-61884
HIGHKEVpublished 2025-10-12 03:15 UTC · 10 months ago · modified 2026-06-17 09:51 UTC
7.5
CVSS / 10
// description
Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
// required action (CISA KEV)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
added 2025-10-20 00:00 UTC
// weaknesses (CWE)
- CWE-22
- CWE-93
- CWE-287
- CWE-444
- CWE-501
- CWE-918
// references (4)
- https://www.oracle.com/security-alerts/alert-cve-2025-61884.html
- https://blogs.oracle.com/security/post/apply-july-2025-cpu
- https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61884