CVE-2025-61882
Oracle E-Business Suite Análise e mitigação de vulnerabilidades

Visão geral

CVE-2025-61882 is a critical vulnerability in Oracle E-Business Suite's Concurrent Processing product (BI Publisher Integration component) affecting versions 12.2.3-12.2.14. Discovered in August 2025 and publicly disclosed on October 4, 2025, this vulnerability allows unauthenticated attackers with network access to achieve remote code execution without requiring user credentials (Oracle Security Alert, NVD).

Detalhes técnicos

The vulnerability has received a CVSS 3.1 base score of 9.8 (Critical), with high impacts on confidentiality, integrity, and availability. The exploit chain involves multiple steps including server-side request forgery (SSRF), CRLF injection, authentication bypass, and malicious XSLT template execution. The attack begins with an HTTP POST request to /OAHTML/SyncServlet for authentication bypass, followed by GET and POST requests to /OAHTML/RF.jsp and /OA_HTML/OA.jsp to upload and execute a malicious XSLT template (WatchTowr Labs, CrowdStrike Blog).

Impacto

Successful exploitation of this vulnerability can result in complete takeover of Oracle Concurrent Processing, allowing attackers to execute arbitrary code remotely, establish persistence through web shells, and potentially exfiltrate sensitive data from affected systems. The vulnerability has been actively exploited in data theft and extortion campaigns (Oligo Security).

Mitigação e soluções alternativas

Oracle strongly recommends immediate application of the security updates provided in the Security Alert. The October 2023 Critical Patch Update is a prerequisite for applying these updates. Additional recommended mitigations include investigating outbound connections from Oracle EBS instances, searching for malicious templates in xdotemplatesvl, investigating suspicious UserID 0 and UserID 6 sessions, temporarily disabling internet access for exposed Oracle EBS services, and securing EBS instances with a web application firewall (Oracle Security Alert).

Reações da comunidade

The vulnerability has garnered significant attention in the cybersecurity community, particularly due to its active exploitation by the Clop ransomware group. The exploit was initially advertised for sale on the Dark Web for approximately $70,000 in June 2025, before being actively used in attacks. The public disclosure and patch release have led to increased concern about widespread exploitation attempts (Oligo Security).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado Oracle E-Business Suite Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2025-61882CRITICAL9.8
  • Oracle E-Business SuiteOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
SimNãoOct 05, 2025
CVE-2025-30727CRITICAL9.8
  • Oracle E-Business SuiteOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NãoNãoApr 15, 2025
CVE-2025-21516HIGH8.1
  • Oracle E-Business SuiteOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NãoSimJan 21, 2025
CVE-2025-21506HIGH8.1
  • Oracle E-Business SuiteOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NãoSimJan 21, 2025
CVE-2025-50090MEDIUM5.4
  • Oracle E-Business SuiteOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NãoNãoJul 15, 2025

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adão FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades