Skip to content
COOEY

FAIL › dossier

E-Business Suite

PRODUCT

· dossier confidence 40%

PROFILE
CategorycosmeticsWhat they doEstée Lauder is a global leader in the skincare, makeup, fragrance, and hair care industries.HQNew York, NY, USA Websitehttps://www.estee-lauder.com/ ↗
SECURITY POSTURE

The company has faced multiple security breaches, indicating a potential lack of robust security measures.

Notable failures
  • CVE-2025-61884: Unpatched SSRF vulnerability in Oracle Configurator led to remote code execution.
  • CVE-2025-61882: Unauthenticated remote attacker took control of BI Publisher Integration, resulting in full system compromise.
  • CVE-2022-21587: Unauthenticated attacker compromised Oracle E-Business Suite via an unspecified vulnerability in Web Applications Desktop Integrator.
  • CVE-2026-46817: Unauthenticated attacks via HTTP exposed Oracle E-Business Suite to potential takeover.
Patterns: Repeated exploitation of unpatched vulnerabilities in Oracle E-Business Suite.; Lack of proper authentication controls leading to unauthorized access.
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2025-10-20 CVE-2025-61884 critical Oracle E-Business Suite's unpatched SSRF vulnerability in Oracle Configurator was actively exploited in the wild without authentication, enabling remote code execution and ransomware attacks.
2025-10-06 CVE-2025-61882 critical An unauthenticated remote attacker can take over Oracle E-Business Suite's BI Publisher Integration component via HTTP, leading to full system compromise.
2023-02-02 CVE-2022-21587 critical An unauthenticated attacker could compromise Oracle E-Business Suite via an unspecified vulnerability in Oracle Web Applications Desktop Integrator.
2026-07-15 CVE-2026-46817 high Oracle E-Business Suite exposed to unauthenticated attacks via HTTP, potentially allowing takeover of Oracle Payments.
Open questions: How has Oracle addressed the noted security failures? · What is the current state of security in Oracle's E-Business Suite?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-25 03:45:24.920605+00:00