logo

Oracle releases emergency patch for new E-Business Suite flaw

ID: 6051d6b7-5b2e-5ef3-9455-278cce846cf0

STIX ID: report--6051d6b7-5b2e-5ef3-9455-278cce846cf0

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-13

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Oracle released an out-of-band emergency patch for CVE-2025-61884, a remotely exploitable, unauthenticated information-disclosure flaw in E-Business Suite 12.2.3–12.2.14 (CVSS 7.5), and urged immediate application; the report notes a related EBS zero-day (CVE-2025-61882) has been exploited by the Clop extortion group in data-theft campaigns, PoC exploit code was leaked, and internet-facing EBS instances are actively targeted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.