Umbra Wiki cve cve/CVE-2025-61884
Back to wiki

CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

provenance: imported · CVE: CVE-2025-61884

CVE-2025-61884: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Oracle
Product E-Business Suite
Date added 2025-10-20
Due date 2025-11-10
Ransomware campaign use Known

Description

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-61884
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog