The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle's E-Business Suite to its Known Exploited Vulnerabilities catalog, confirming it is being actively exploited in attacks. The flaw, identified as CVE-2025-61884, is a server-side request forgery (SSRF) issue in the Oracle Configurator component that can be exploited by a remote attacker without authentication to access sensitive data. This vulnerability poses a significant threat to organizations that use the widely deployed E-Business Suite. The active exploitation of this flaw could allow attackers to bypass network controls and access internal services, leading to potential data exfiltration and deeper network penetration. Following the confirmation of active exploitation, CISA has mandated that federal agencies must apply Oracle's security patches or implement mitigations by November 10, 2025.
CISA Warns of Actively Exploited Critical Vulnerability in Oracle E-Business Suite
ORCL
Related News
ORCL
Developers Pressure Oracle to Cede Control of MySQL Amid AI-Era Stagnation Fears
ORCL
Oracle Stock Rises on Hedge Fund Buying and Tech Sector Recovery
ORCL
Oracle stock rises in pre-market trading amid broader tech recovery and upcoming earnings catalyst
ORCL
Oracle Shares Slide 3.9% as AI Debt and Fraud Lawsuits Cloud Growth Outlook
ORCL