CVE-2025-61884HIGH 7.5CISA KEVEPSS p99.9%

CVE-2025-61884Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Oracle / E-Business Suite

Description

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

Scoring

CVSS 3.17.5 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS97.58% probability of exploitation · percentile 99.9% · 2026-06-17T12:03:21Z
Published2025-10-12
Last modified2025-10-27

CISA KEV entry

Added to KEV: 2025-10-20

Underlying weaknesses· 6

CWE-22CWE-93CWE-287CWE-444CWE-501CWE-918

References

  1. https://www.oracle.com/security-alerts/alert-cve-2025-61884.html
  2. https://blogs.oracle.com/security/post/apply-july-2025-cpu
  3. https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/
  4. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61884

6

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live
WeaknessImproper Authenticationcwe-2870%live
WeaknessInconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')cwe-4440%live
WeaknessTrust Boundary Violationcwe-5010%live
WeaknessServer-Side Request Forgery (SSRF)cwe-9180%live
WeaknessImproper Neutralization of CRLF Sequences ('CRLF Injection')cwe-930%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryOracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerabilitykev-cve-2025-618840%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Oracle E-Business Suite Unspecified Vulnerability
CVE
CVE-2025-21506
CVE
CVE-2025-21516
CVE
CVE-2025-30743
CVE
CVE-2025-30727
CVE
CVE-2025-28062
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.