Active exploitation of vulnerability affecting Oracle E-Business Suite
The NCSC is encouraging UK organisations to take immediate action to mitigate a vulnerability (CVE-2025-61882) affecting Oracle E-Business Suite.
What has happened?
Oracle has published a security update to address an unauthenticated remote vulnerability (CVE-2025-61882) affecting Oracle E-Business Suite (EBS). This vulnerability is being actively exploited and may allow remote code execution.
CVE-2025-61882 is a vulnerability in the BI Publisher Integration component of Oracle Concurrent Processing within Oracle E-Business Suite. An unauthenticated attacker can send specially crafted HTTP requests to the affected component resulting in full system compromise. No user interaction is required.
The NCSC will continue to monitor for any impact of this vulnerability on UK organisations.
Who is affected?
Organisations using Oracle E-Business Suite (EBS) versions 12.2.3 to 12.2.14 are affected. Organisations who have exposed Oracle EBS to the internet are at greatest risk.
What should I do?
The NCSC recommends following vendor best practice advice in the mitigation of vulnerabilities. In this case, if you use Oracle EBS, you should take the following priority actions:
Perform a compromise assessment. IoCs have been published in Oracle’s advisory.
If you believe you have been compromised, you should contact Oracle PSIRT and if you are in the UK, also report it to the NCSC.
If your organisation is in the UK, you can sign up to the free NCSC Early Warning service to receive notifications of potential threats on your network.
The NCSC Vulnerability Disclosure Toolkit helps organisations of all sizes with the essential components of implementing a vulnerability disclosure process.