Umbra Wiki cve cve/CVE-2025-61882
Back to wiki

CVE-2025-61882 — Oracle E-Business Suite Unspecified Vulnerability

provenance: imported · CVE: CVE-2025-61882

CVE-2025-61882: Oracle E-Business Suite Unspecified Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Oracle
Product E-Business Suite
Date added 2025-10-06
Due date 2025-10-27
Ransomware campaign use Known

Description

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

https://www.oracle.com/security-alerts/alert-cve-2025-61882.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61882

Weakness behind it

CISA has not recorded a CWE for this entry, so the CVE → CWE → CAPEC → ATT&CK chain cannot be walked from here. That is a gap in the catalogue, not evidence the vulnerability has no weakness class — check the NVD record below.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-61882
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →

Related pages