Summary
Oracle E-Business Suite's Concurrent Processing / BI Publisher Integration is vulnerable to an unauthenticated remote code execution chain reachable through exposed web endpoints. Oracle, CrowdStrike, and Google/Mandiant report that attackers can combine authentication bypass, request smuggling/SSRF-style requests, and malicious XSLT template processing to reach arbitrary code execution. In-the-wild exploitation has been tied to extortion activity and data theft against internet-exposed EBS systems.
Why Emergency Fix?
6/6Exploitation Details
Execute arbitrary commands as the Oracle EBS application user and establish persistence or steal data.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Oracle E-Business Suite | 12.2.3 through 12.2.14 |
Enterprise software suite for finance, HR, procurement, supply chain, and other back-office operations. The vulnerable area is Concurrent Processing with BI Publisher Integration, which generates reports and manages templates.
Affected ComponentConcurrent Processing's BI Publisher Integration, including template upload, preview, and XSLT/template-processing flows exposed through EBS web endpoints.
Concurrent Processing's BI Publisher Integration, including template upload, preview, and XSLT/template-processing flows exposed through EBS web endpoints.
Affected Endpoints(5)/OA_HTML/SyncServlet, /OA_HTML/RF.jsp…
Temporarily remove internet exposure from EBS services and place the application behind a WAF until patching is complete; this may disrupt external access and integrations.
Temporarily remove internet exposure from EBS services and place the application behind a WAF until patching is complete; this may disrupt external access and integrations.
Not available
Apply Oracle's emergency Security Alert for Oracle E-Business Suite 12.2.3-12.2.14. Oracle notes that the October 2023 Critical Patch Update is a prerequisite for applying this fix.
Apply Oracle's emergency Security Alert for Oracle E-Business Suite 12.2.3-12.2.14. Oracle notes that the October 2023 Critical Patch Update is a prerequisite for applying this fix.
Probability of exploitation in the next 30 days
Worse than 100% of all CVEs
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (1)
- •cpe:2.3:a:oracle:concurrent_processing:*:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| www.oracle.com | Oracle Security Alert Advisory - CVE-2025-61882 |
| blogs.oracle.com | Apply Oracle Security Alert CVE-2025-61882 for Oracle E-Business Suite (EBS) |
| www.oracle.com | Oracle Critical Patch Update Advisory - October 2025 |
| cloud.google.com | Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign |
| www.crowdstrike.com | CrowdStrike Identifies Campaign Targeting Oracle E-Business Suite via Zero-Day Vulnerability Tracked as CVE-2025-61882 |
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
| www.tenable.com | CVE-2025-61882 |
| threatprotect.qualys.com | Oracle E-Business Suite Remote Code Execution Vulnerability Exploited in the Wild (CVE-2025-61882) |
| www.rapid7.com | Oracle E-Business Suite: CVE-2025-61882: Critical Patch Update |
| github.com | rxerium/CVE-2025-61882-CVE-2025-61884 |
| github.com | MindflareX/CVE-2025-61882-POC |
Priority History
Initial analysis
Reassessed to Fix Soon
Elevated — additional risk factors confirmed