Overview
CVE-2025-61882 is a critical unauthenticated remote code execution vulnerability in Oracle E-Business Suite (EBS), specifically within the Concurrent Processing component’s BI Publisher Integration. It affects versions 12.2.3 through 12.2.14.
Severity and Impact
- CVSS Score: 9.8 (Critical)
- Attack Vector: Network (HTTP)
- Authentication Required: None
- User Interaction: None
- Impact: Full system compromise—confidentiality, integrity, and availability all at risk.
Exploitation Status
- Actively exploited in the wild as a zero-day.
- Linked to Cl0p ransomware extortion campaigns targeting Oracle EBS customers.
Affected Systems
- Oracle E-Business Suite versions 12.2.3 to 12.2.14.
- Any deployment exposing the BI Publisher HTTP endpoints is vulnerable.
Recommended Actions
- Immediate patching: Apply Oracle’s Security Alert updates. The October 2023 Critical Patch Update is a prerequisite.
- Upgrade: Ensure systems are on supported versions under Premier or Extended Support.
- Detection and Response: Review Oracle’s indicators of compromise (IOCs) for threat hunting and containment.
Business Implications
- Operational Risk: Potential disruption of ERP, financials, HR, and supply chain systems.
- Data Exposure: Unauthorized access to sensitive business data.
- Reputation and Compliance: Increased risk of regulatory violations and reputational damage due to ransomware extortion.
Technical Details:
Vulnerable Component
The flaw resides in the BI Publisher Integration used by Oracle Concurrent Processing. This component handles report generation and formatting and is accessible via HTTP endpoints. Improper input validation and unsafe deserialization allow attackers to inject malicious payloads.
Exploitation Details
- Exploit Type: Remote code execution via crafted HTTP request
- Technique: Likely involves unsafe deserialization or command injection through XML or SOAP payloads
- Impact: Full compromise of the EBS application server, including access to ERP, HR, financial, and supply chain data
- Observed Activity: Active exploitation in the wild by ransomware groups (e.g., Cl0p) targeting exposed Oracle EBS instances
Indicators of Compromise (IOCs)
Oracle has published IOCs including:
- Suspicious IP addresses
- Malicious commands executed via concurrent manager
- Dropped files and modified configurations
Mitigation and Patching
- Patch Requirement: October 2023 Critical Patch Update must be applied first
- Security Alert Patch: Apply the CVE-2025-61882 patch immediately
- Support Requirement: Only available for versions under Premier or Extended Support
Recommendations
- Immediately patch affected systems
- Audit exposed HTTP endpoints and restrict access
- Monitor for IOCs and anomalous activity in concurrent processing logs
- Consider upgrading to the latest supported EBS version












