logo

Critical Oracle EBS Flaw Could Expose Sensitive Data

ID: 4e3a999d-9a7f-52dd-9348-e4f1137412f5

STIX ID: report--4e3a999d-9a7f-52dd-9348-e4f1137412f5

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2025-10-13

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

Oracle published a patch for CVE-2025-61884, a CVSS 7.5 authentication-bypass in the Oracle E-Business Suite Configurator Runtime UI that can be exploited remotely without credentials to access sensitive configuration and system data; the advisory urges immediate patching, access restriction, logging, and other hardening measures and notes prior exploitation of a related CVE (CVE-2025-61882) in data-theft/extortion campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.