CRITICAL

CVE-2025-61882

Oracle Concurrent Processing 2025-10-05 CVSS v3.1
CVSS
9.8
KEV

Description

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Summary dbcve.org

Unauthenticated remote code execution vulnerability in Oracle E-Business Suite Concurrent Processing BI Publisher Integration allows complete system compromise via HTTP network attacks. The flaw enables an unauthenticated remote attacker to achieve full takeover of the affected Oracle Concurrent Processing component.

Mitigation

Apply Oracle Critical Patch Update (CPU) or specific security patch for CVE-2025-61882 to all affected Oracle E-Business Suite instances (versions 12.2.3-12.2.14). If immediate patching is not possible, restrict network access to Oracle Concurrent Processing endpoints.

Weakness (CWE)

CWE-287 Improper Authentication

EPSS Score

99.73%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE