Oracle E-Business Suite Unspecified Vulnerability
Critical CVSS 9.8 Listed in CISA KEV
Summary
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Oracle:E-Business Suite
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2025-61882 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://www.oracle.com/security-alerts/alert-cve-2025-61882.html reference
- https://blogs.oracle.com/security/post/apply-july-2025-cpu Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61882 US Government Resource
- https://www.crowdstrike.com/en-us/blog/crowdstrike-identifies-campaign-targeting-oracle-e-business-suite-zero-day-CVE-2025-61882/ Press/Media Coverage
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD