CVE-2025-61884 is a critical vulnerability affecting the Runtime UI component of Oracle Configurator within Oracle E-Business Suite versions 12.2.3 through 12.2.14. This easily exploitable flaw allows unauthenticated attackers with network access to compromise Oracle Configurator, leading to a high confidentiality impact, including unauthorized access to critical or all accessible data. Rated with a CVSS 3.1 Base Score of 7.5 (High), its attack vector is network-based with low complexity and no required privileges or user interaction. The vulnerability is actively exploited in the wild, confirmed by CISA and linked to ransomware campaigns, with Nuclei templates available and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.14CPE matchmatch criteria | cpe:2.3:a:oracle:configurator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.