CVE-2025-61884Active Exploitation(oracle / configurator)

LOWCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for oracle configurator systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-11-10. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22CWE-93CWE-287CWE-444CWE-501CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • configurator

Threat summary

  • Active exploitation appears in 2 classified signals
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-09); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
configurator

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-09: 1Mentions · 2026-04-08: 1Mentions · 2026-06-25: 1Mentions · 2026-07-22: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-04-08: 103-0904-0806-2507-22
Signal classification2 categories
Active Exploitation
250.0%
Disclosure
250.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-091
Active Exploitation1
2026-04-081
Active Exploitation1
2026-06-251
Disclosure1
2026-07-221
Disclosure1
Full discourse4 posts
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    Team Cymru’s report identifies the 25 most frequent CVE exploitation attempts observed over a 14‑day period, indicating that these vulnerabilities are actively being targeted in the wild.

    070921.2K
    5.5K followersView on X
  • Security Aid@SecurityAid
    Active Exploitation

    CISA Confirms Exploitation of Latest Oracle EBS Vulnerability  The cybersecurity agency has added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog. The post CISA Confirms Exploitation of Latest Oracle EBS Vulnerability  appeared first on SecurityWeek. ​The ... https://t.co/69KxTg69up

    Post summary

    CISA has confirmed that CVE-2025-61884 is being exploited in the wild, adding it to its Known Exploited Vulnerabilities catalog.

    1000098
    124 followersView on X
  • @pedri77@pedri77
    Disclosure

    Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its E-Business Suite that it said could allow unauthorized access to sensitive data. The vulnerability, tracked as CVE-2025-61884, ca... https://f.mtr.cool/vylscoenxc

    Post summary

    Oracle issued a security alert for CVE-2025-61884, noting it may lead to unauthorized access of sensitive data in its E‑Business Suite, but no exploit details or patch information were included.

    0000056
    2.1K followersView on X
  • @pedri77@pedri77
    Disclosure

    Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its E-Business Suite that it said could allow unauthorized access to sensitive data. The vulnerability, tracked as CVE-2025-61884, ca... https://f.mtr.cool/ecjuhymrra

    Post summary

    The passage announces a newly identified Oracle E‑Business Suite flaw (CVE‑2025‑61884) that could enable unauthorized data access, without providing further technical details or remediation guidance.

    0000048
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleconfigurator---

Explore more