Cyber Security News

Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication

Oracle has disclosed a critical vulnerability in its E-Business Suite that enables unauthenticated attackers to remotely access sensitive data, raising alarms for enterprises relying on the platform for core operations.

Tracked as CVE-2025-61884, the flaw affects the Oracle Configurator component and was detailed in a security alert released on October 11, 2025.

This comes just days after another exploited E-Business Suite vulnerability, CVE-2025-61882, highlighting ongoing security challenges in Oracle’s enterprise resource planning software.

The issue allows hackers to bypass authentication over HTTP, potentially exposing configuration data critical to business processes like finance and supply chain management.​

Oracle E-Business Suite RCE Vulnerability

CVE-2025-61884 resides in the Runtime UI of Oracle Configurator, a module used for managing product and service configurations within E-Business Suite.

Attackers with network access can exploit this flaw without credentials, leading to unauthorized data retrieval or enumeration. The vulnerability stems from an authentication bypass mechanism, though specific technical details like affected endpoints remain undisclosed to prevent widespread abuse.

Oracle rates it with a CVSS 3.1 base score of 7.5, classifying it as high severity due to its ease of exploitation. No credits are given to external researchers, suggesting internal discovery by Oracle’s security team.​

The following table summarizes key aspects of the vulnerability:

CVE IDAffected ComponentProtocolCVSS Base ScoreAttack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability ImpactSupported Versions
CVE-2025-61884Oracle Configurator (Runtime UI)HTTP7.5NetworkLowNoneNoneUnchangedHighNoneNone12.2.3-12.2.14 ​

This structured breakdown underscores the remote, unauthenticated nature of the threat, making it accessible to any internet-facing deployment.​

Successful exploitation could grant hackers complete access to all Oracle Configurator data, including sensitive business configurations that drive operational decisions.

For organizations in sectors like manufacturing or retail, this means exposure of proprietary models, pricing strategies, and customer details, potentially leading to competitive disadvantages or regulatory violations.

The high confidentiality impact without affecting integrity or availability positions it as a data exfiltration vector rather than a disruptive attack.

Given the recent exploitation of CVE-2025-61882 by ransomware groups like Cl0p, security experts warn that CVE-2025-61884 could follow suit, especially as proof-of-concepts for similar flaws circulate. Enterprises with unpatched E-Business Suite instances face elevated risks, particularly if exposed to the public internet.​

Mitigations

Oracle urges immediate application of the released patches for versions 12.2.3 through 12.2.14, available via the Security Alert program for supported releases under Premier or Extended Support.

Customers on older versions should upgrade to maintained branches, as earlier releases like 12.1.3 may also be vulnerable despite lacking testing.

Additional defenses include network segmentation to limit HTTP access to the Configurator UI and monitoring for anomalous requests.

Oracle’s advisory provides detailed patch instructions through support documents, emphasizing the Lifetime Support Policy for ongoing protection.

While no active exploitation has been confirmed for this CVE, the pattern of rapid E-Business Suite attacks demands swift action to safeguard sensitive resources.​

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

1 hour ago

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

1 hour ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

2 hours ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

2 hours ago

Top 10 Best SAST Tools in 2026 [Ranked & Scored]

The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…

2 hours ago

Top 10 Best Just-in-Time (JIT) Access Tools in 2026 [Ranked & Scored]

Credentials that always work are credentials worth stealing which is why mitigating how attackers exploit…

3 hours ago