CVE-2025-61882

Critical9.8Published on October 5, 2025

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Oct 6, 2025
  • US federal agencies must remediate it by Oct 27, 2025 (BOD 22-01)
  • Attacked 1 day before the vulnerability was made public
  • Confirmed by sensors, not only by reports
  • Used in ransomware campaigns

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Sep 17, 2026 Sep 14, 2026 Sep 13, 2026 Sep 10, 2026 Sep 6, 2026 Sep 3, 2026

CVSS score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-287
Vendorsoracle

Affected products

VendorsProductVersions
oracleconcurrent processing<= 12.2.14

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database