CVE-2025-61882CRITICAL 9.8CISA KEVEPSS p100.0%
CVE-2025-61882Oracle E-Business Suite Unspecified Vulnerability
Oracle / E-Business Suite
Description
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.72% probability of exploitation · percentile 100.0% · 2026-06-15T12:03:41Z |
| Published | 2025-10-05 |
| Last modified | 2025-10-27 |
CISA KEV entry
Added to KEV: 2025-10-06
Underlying weaknesses· 1
References
- https://www.oracle.com/security-alerts/alert-cve-2025-61882.html
- https://blogs.oracle.com/security/post/apply-july-2025-cpu
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61882
- https://www.crowdstrike.com/en-us/blog/crowdstrike-identifies-campaign-targeting-oracle-e-business-suite-zero-day-CVE-2025-61882/
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authenticationcwe-287 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Oracle E-Business Suite Unspecified Vulnerabilitykev-cve-2025-61882 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.