CVE-2025-61884: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
Other sources
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61884?
CVE-2025-61884 is considered highly severe due to its potential for unauthenticated remote code execution.
How do I fix CVE-2025-61884?
To fix CVE-2025-61884, apply the latest security patches provided by Oracle for the Oracle Configurator product.
Who is affected by CVE-2025-61884?
CVE-2025-61884 affects users of Oracle Configurator versions 12.2.3 to 12.2.14.
What type of attack does CVE-2025-61884 enable?
CVE-2025-61884 enables unauthenticated attackers to exploit the vulnerability over HTTP.
Is CVE-2025-61884 easy to exploit?
Yes, CVE-2025-61884 is deemed easily exploitable, allowing attackers to compromise systems with minimal effort.