CVE-2025-61756: High severity Oracle Financial Services Analytical Applications Infrastructure vulnerability
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61756?
CVE-2025-61756 has been classified as a high-severity vulnerability due to its exploitability by unauthenticated users.
How do I fix CVE-2025-61756?
To fix CVE-2025-61756, you should upgrade to the latest patched version of Oracle Financial Services Analytical Applications Infrastructure provided by Oracle.
Which versions are affected by CVE-2025-61756?
The affected versions of Oracle Financial Services Analytical Applications Infrastructure are 8.0.7.9, 8.0.8.7, and 8.1.2.5.
What causes CVE-2025-61756?
CVE-2025-61756 is caused by a vulnerability in the System Configuration component of Oracle Financial Services Analytical Applications Infrastructure.
Is CVE-2025-61756 exploitable remotely?
Yes, CVE-2025-61756 is easily exploitable remotely, allowing attackers to exploit the vulnerability without authentication.