📣 Send us your press release
Site updates every 15 minutes
Technology

Oracle EBS Vulnerability CVE-2025-61882 Actively Exploited

Picus Security reports a critical vulnerability in Oracle E-Business Suite (CVE-2025-61882) allowing unauthenticated remote code execution. The vulnerability is being actively exploited by threat actors.

2 October 2026
Oracle EBS Vulnerability CVE-2025-61882 Actively Exploited

Cybersecurity firm Picus Security has detailed a critical vulnerability within Oracle E-Business Suite (EBS), identified as CVE-2025-61882. This flaw enables unauthenticated remote code execution and is currently being actively exploited in the wild.

Oracle released a security advisory for CVE-2025-61882 on October 4, 2025. The exploit chains together multiple weaknesses, including Server-Side Request Forgery (SSRF), CRLF injection, authentication bypass, and unsafe XSLT processing, to achieve code execution on affected systems.

The vulnerability impacts Oracle EBS versions 12.2.3 through 12.2.14. It carries a CVSS score of 9.8, classifying it as critical. Picus Security highlighted that threat actors, including the Cl0p ransomware group, have been observed actively exploiting this vulnerability, underscoring the urgency for remediation.

Picus Security's analysis outlines the exploit chain, which begins with an SSRF vulnerability in the UiServlet endpoint. This allows an attacker to force the server to make outbound requests to arbitrary locations. Subsequently, CRLF injection is used to manipulate HTTP requests and headers, enabling the attacker to smuggle further data to downstream services. The attack culminates in accessing and exploiting internal JavaServer Pages (JSP) to achieve remote code execution.

Organizations using affected versions of Oracle EBS are strongly advised to apply Oracle's patches or implement available mitigations without delay to protect their systems.

Original source: picussecurity.com