Oracle released an urgent security update over the weekend to fix a new vulnerability in its E-Business Suite (EBS) software that could be exploited remotely and reveal sensitive information . The issue is located in the Runtime UI component and is listed as CVE-2025-61884 .

According to the company's announcement, the vulnerability affects EBS versions from 12.2.3 to 12.2.14, and could allow unauthorized attackers to gain access and steal sensitive data, without the use of a username or password.
“ This issue is exploitable remotely and without authentication — it can be exploited over a network — so customers should apply updates or mitigations immediately ,” Oracle said . Rob Duhart , Oracle’s Chief Security Officer, confirmed that the vulnerability carries a CVSS score of 7.5 and, if successfully exploited, could grant access to critical resources.
See also: Axis Communications: Vulnerability exposes Azure Storage Account credentials
The release of this update comes about two weeks after a ransomware campaign group Clop, which targeted company executives — and which Oracle has linked to previous EBS vulnerabilities, such as CVE-2025-61882. A CrowdStrike spokesperson commented that Clop had been exploiting CVE-2025-61882 as a zero-day since early August.
Clop has a history of extortion campaigns with zero-day attacks on platforms such as Accellion FTA, GoAnywhere, Cleo, and MOVEit Transfer — with the latter affecting over 2,770 organizations.
So far, Oracle has not labeled the CVE-2025-61884 as "exploitable" online, nor has it directly linked it to the previous vulnerability CVE-2025-61882. However, experts recommend that the update for CVE-2025-61884 be applied immediately.
See also: PoC Exploit for Lenovo code execution vulnerability

Τι πρέπει να κάνουν οι οργανισμοί — Οδηγίες αντιμετώπισης
1. Άμεση εφαρμογή ενημερώσεων / mitigations
Even though Oracle has not identified CVE-2025-61884 as already exploited, proactively applying the update is critical. Especially in EBS environments that are exposed to the internet, latency is a serious vulnerability.
2. Αναζήτηση επιπτώσεων (threat hunting)
Οι διαχειριστές θα πρέπει να διεξάγουν έλεγχο (hunting) για ανωμαλίες που αφορούν συσκευές Oracle:
- unusual HTTP requests to endpoints
/OA_HTML/* - XML / XSLT structures
- unwanted outbound connections (reverse shells)
- web shell files or scripts that should not exist
3. No exposure to the internet without protection
Oracle EBS instances should avoid direct exposure to the Internet. Access should be via VPN, firewall, TLS with strong authentication and network segmentation so that the impact of a potential breach is limited.
4. Regular vulnerability checks & updates
Oracle has now proven itself to be a target of active attacks. Regular vulnerability scanning, prompt application of Critical Patch Updates, and monitoring of security mechanisms (SIEM, EDR) are essential.
See also: Happy DOM Vulnerability: 2.7 Million Users at Risk
5. Training & incident response plan
Support security teams and training of administrators so that they recognize signs of malicious activity or unusual patterns. There must be a ready incident response plan (IR plan) and a recovery process.

6. Αξιολόγηση επιπτώσεων και αναφορά
Any suspicion that a system may have been compromised should be investigated immediately — including assessing the volume of data that may have been exposed, the impact on compliance (GDPR, SOX, or other regulatory requirements), and the potential for legal or financial consequences.
Organizations that use Oracle EBS must take seriously that security is no longer “a one‑time update package” — but a continuous process of monitoring, defense, and adaptation in the constantly evolving realm of cybercrime.
Source: www.bleepingcomputer.com
