logo

Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign

ID: accdec49-3dcb-5ffb-bd61-193042636297

STIX ID: report--accdec49-3dcb-5ffb-bd61-193042636297

Feed Name: Threat Intelligence

Threat Score
75/100

Date Published: 2025-10-09

Date Updated: 2026-04-27

Author: Mandiant

...
...

Technical analysis of active exploitation attempts against Oracle E-Business Suite (EBS) observed July–August 2025: investigators observed activity targeting /OA_HTML/configurator/UiServlet and /OA_HTML/SyncServlet leading to unauthenticated remote code execution via a chain of primitives (SSRF, CRLF, auth bypass, XSL injection). The report links observed IPs and leaked exploit artifacts to in-the-wild activity, documents sample payloads (e.g., Bash reverse shell), and notes that Oracle patches released in July and October 2025 likely mitigate known exploitation chains while some exploitation attempts continued against unpatched systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.