Story perspectives
Oracle Warns of Critical E-Business Suite Vulnerability
10/13/2025
45 5
1 of 1
Story summary
- Oracle has identified a vulnerability in its E-Business Suite, CVE-2025-61884, enabling unauthorized access to sensitive data via HTTP and affecting versions 12.2.3 to 12.2.14.
- Rob Duhart, Oracle Chief Security Officer, urged updates.
- Announcement follows breaches linked to CVE-2025-61882 that exploited a zero-day to deploy malware and extort companies.
- Investigations by Google Threat Intelligence Group and Mandiant indicate the attacks may have begun as early as July 2025, signaling a threat.
