CVE-2025-61882
Description
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Summary dbcve.org
Unauthenticated remote code execution vulnerability in Oracle E-Business Suite Concurrent Processing BI Publisher Integration allows complete system compromise via HTTP network attacks. The flaw enables an unauthenticated remote attacker to achieve full takeover of the affected Oracle Concurrent Processing component.
Mitigation
Apply Oracle Critical Patch Update (CPU) or specific security patch for CVE-2025-61882 to all affected Oracle E-Business Suite instances (versions 12.2.3-12.2.14). If immediate patching is not possible, restrict network access to Oracle Concurrent Processing endpoints.