EXPOSURES › CVE-2025-61884
CVE-2025-61884
CRITICAL ⌖ ON CISA KEV · EXPLOITEDOracle E-Business Suite's unpatched SSRF vulnerability in Oracle Configurator was actively exploited in the wild without authentication, enabling remote code execution and ransomware attacks.
Oracle E-Business Suite's unpatched SSRF vulnerability in Oracle Configurator was actively exploited in the wild without authentication, enabling remote code execution and ransomware attacks. DIB organizations must ensure all Oracle E-Business Suite instances are patched and monitored for exploitation, as this vulnerability allows attackers to execute arbitrary code without needing credentials. The failure highlights the severe risks of relying on unpatched software, especially in critical business environments.
Shame score — The vulnerability was actively exploited in the wild without authentication, enabling ransomware attacks and remote code execution, which is a severe and avoidable failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |