A vulnerability has been discovered in Oracle E-Business Suite, which could allow for remote code execution. Oracle E-Business Suite (EBS) is a comprehensive suite of integrated business applications that runs core enterprise functions. Successful exploitation of this vulnerability could allow an actor to execute code in the context of the affected component. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
THREAT INTELLIGENCE:
Oracle is aware that CVE-2025-61882 has been exploited in the wild.
SYSTEMS AFFECTED:
-
Oracle E-Business Suite, versions 12.2.3-12.2.14
RISK:
Government:
-
Large and medium government entities: High
-
Small government entities: Medium
Businesses:
-
Large and medium business entities: High
-
Small business entities: Medium
Home users: Low
TECHNICAL SUMMARY:
A vulnerability has been discovered in Oracle E-Business Suite, which could allow for remote code execution. Details of the vulnerability are as follows:
Tactic: Initial Access (TA0001):
Technique: Exploit Public-Facing Application (T1190):
-
Oracle E-Business Suite was found to be susceptible to a vulnerability that allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. (CVE-2025-61882)
Successful exploitation of this vulnerability could allow an actor to execute code in the context of the affected component. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
RECOMMENDATIONS:
We recommend the following actions be taken:
-
Apply appropriate updates provided by Oracle or other vendors which use this software to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
-
Safeguard 7.1 : Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
-

