CVE-2025-61884
KEV
🔴 Łataj teraz
Luka w Oracle Configurator umożliwia nieautoryzowany dostęp do krytycznych danych.
CVSS
7.5
EPSS
97.8%
Exploit
weaponized
Vendor
oracle
Opis źródłowy (NVD)
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 97.8% |
| Opublikowano (NVD) | 2025-10-12 03:15:34 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:36 UTC |
Referencje
- https://www.oracle.com/security-alerts/alert-cve-2025-61884.html (secalert_us@oracle.com) [Vendor Advisory]
- https://blogs.oracle.com/security/post/apply-july-2025-cpu (134c704f-9b21-4f2e-91b3-4a467353bcc0) [Vendor Advisory]
- https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/ (134c704f-9b21-4f2e-91b3-4a467353bcc0) [Exploit, Press/Media Coverage]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61884 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]