Oracle releases emergency patch for new E-Business Suite flaw
ID: 6051d6b7-5b2e-5ef3-9455-278cce846cf0
STIX ID: report--6051d6b7-5b2e-5ef3-9455-278cce846cf0
Feed Name: Bleeping Computer
Threat Score
Oracle released an out-of-band emergency patch for CVE-2025-61884, a remotely exploitable, unauthenticated information-disclosure flaw in E-Business Suite 12.2.3–12.2.14 (CVSS 7.5), and urged immediate application; the report notes a related EBS zero-day (CVE-2025-61882) has been exploited by the Clop extortion group in data-theft campaigns, PoC exploit code was leaked, and internet-facing EBS instances are actively targeted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
