logo

Lessons from Oracle E-Business Suite Hack That Allegedly Compromises Nearly 30 Organizations Worldwide

ID: e352aad6-177f-5f14-82a9-f1f063984690

STIX ID: report--e352aad6-177f-5f14-82a9-f1f063984690

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-11-20

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A zero-day (CVE-2025-61882, CVSS 9.8) in Oracle E-Business Suite was actively exploited in mid-2025 to obtain unauthenticated RCE via a multi-stage chain (SSRF → CRLF/header injection → path traversal → unsafe XSLT) attributed to Clop/FIN11; exploitation before emergency patches led to widespread data theft and extortion with at least 29 public victims and estimated impact on ~100 organizations, prompting Oracle emergency patches and CISA KEV designation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.