CVE-2025-61882: Oracle E-Business Suite Unspecified Vulnerability
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.
Other sources
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61882?
CVE-2025-61882 is considered to be an easily exploitable vulnerability that can be exploited by unauthenticated attackers.
How do I fix CVE-2025-61882?
To fix CVE-2025-61882, you should update your Oracle E-Business Suite to a version that is not affected by this vulnerability.
Which versions of Oracle E-Business Suite are affected by CVE-2025-61882?
CVE-2025-61882 affects Oracle E-Business Suite versions 12.2.3 through 12.2.14.
What component of Oracle E-Business Suite does CVE-2025-61882 impact?
CVE-2025-61882 impacts the Oracle Concurrent Processing product, specifically its BI Publisher Integration component.
Can CVE-2025-61882 be exploited remotely?
Yes, CVE-2025-61882 can be exploited remotely by an unauthenticated attacker with network access via HTTP.