- Home
- Alerts & Advisories
- Alerts
- Active Exploitation of High Severity Vulnerability in Oracle E-Business Suite
Active Exploitation of High Severity Vulnerability in Oracle E-Business Suite
24 October 2025
Background
Oracle has released security updates to address a high severity vulnerability (CVE‑2025‑61884) in the Oracle Configurator product of its E‑Business Suite.
Impact
Successful exploitation of the server side request forgery (SSRF) vulnerability could allow a remote, unauthenticated attacker to access sensitive resources.
Known Exploitation
The proof-of-concept exploit is reportedly publicly available.
Affected Products
The vulnerability affects Oracle E‑Business Suite versions 12.2.3 through 12.2.14.
Mitigation
Users and administrators of the affected product versions are strongly advised to update to the latest versions immediately.
References
https://www.oracle.com/security-alerts/alert-cve-2025-61884.html
