CVE-2025-61882 is a critical vulnerability in the BI Publisher Integration component of Oracle Concurrent Processing, affecting Oracle E-Business Suite versions 12.2.3 through 12.2.14. This easily exploitable flaw allows an unauthenticated attacker with network access via HTTP to fully compromise the system, leading to complete takeover with severe impacts on confidentiality, integrity, and availability, as reflected by its CVSS 3.1 Base Score of 9.8. The vulnerability is actively exploited, including in known ransomware campaigns, with public exploit modules available for Metasploit and Nuclei templates, and has garnered significant community discussion and media coverage, notably linked to a data breach at the University of Phoenix.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.14CPE matchmatch criteria | cpe:2.3:a:oracle:concurrent_processing:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.