Oracle E-Business Suite RCE Vulnerability
What is the Vulnerability? | CVE-2025-61882 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in the BI Publisher integration of Oracle E-Business Suite’s Concurrent Processing component. The flaw is remotely exploitable over HTTP without authentication, allowing attackers to execute arbitrary code and fully compromise affected systems. |
What is the recommended Mitigation? |
|
What FortiGuard Coverage is available? |
|
Outbreak Alert
Actively exploited as a zero-day in data theft and extortion campaigns, with activity linked to the Cl0p ransomware group. Successful exploitation enables complete takeover of Oracle Concurrent Processing, opening the door to lateral movement, sensitive data exfiltration, and potential ransomware deployment.
Additional Resources
Watchtowr Labs Technical Write-up
Oracle Security Alert Advisory - CVE-2025-61882