• News/
  • https://www.bleepingcomputer.com/news/security/oracle-releases-emergency-patch-for-new-e-business-suite-flaw/

Oracle releases emergency patch for new E-Business Suite flaw

BleepingComputer
·
Sergiu Gatlan
·
Published Oct 13, 2025
·
Updated

Oracle has issued an emergency security update over the weekend to patch another E-Business Suite (EBS) vulnerability that can be exploited remotely by unauthenticated attackers. Tracked as CVE-2025-61884, this information disclosure flaw in the Runtime UI component affects EBS versions 12.2.3 to 12.2.14 and could allow unauthenticated threat actors to steal sensitive data remotely following successful exploitation. "This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password. Oracle strongly recommends that customers apply the updates or mitigations provided by this Security Alert as soon as possible," Oracle said. "This vulnerability has received a CVSS Base Score of 7.5. If successfully exploited, this vulnerability may allow access to sensitive resources, added Rob Duhart, Oracle's Chief Security Officer. Oracle released the CVE-2025-61884 patch almost two weeks after a Clop extortion campaign targeting executives at multiple companies, which the company later linked to EBS vulnerabilities patched in July 2025 and then to another Oracle EBS vulnerability now tracked as CVE-2025-61882. Since then, cybersecurity firm CrowdStrike said they first spotted Clop exploiting CVE-2025-61882 as a zero-day since early August in data theft attacks and warned that other threat groups may have also joined the attacks. watchTowr Labs security researchers have also found that CVE-2025-61882 is a ...

Read full article

Affected Software

12 affected components
Oracle E-Business Suite=12.2.3
Oracle E-Business Suite=12.2.4
Oracle E-Business Suite=12.2.5
Oracle E-Business Suite=12.2.6
Oracle E-Business Suite=12.2.7
Oracle E-Business Suite=12.2.8
Oracle E-Business Suite=12.2.9
Oracle E-Business Suite=12.2.10
Oracle E-Business Suite=12.2.11
Oracle E-Business Suite=12.2.12
Oracle E-Business Suite=12.2.13
Oracle E-Business Suite=12.2.14
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203