Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Nov 10, 2025

CVE-2025-61884

High
EPSS 30.3%CISA KEVRansomware
Oracle/E-Business Suite

Description

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

EPSS — Exploit Probability

30.3%

Higher than 96.6% of all CVEs

Required Action

https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
30.3%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Oct 20, 2025

Added to KEV

Oct 20, 2025

Remediation Due

Nov 10, 2025

Affected Product

Oracle

E-Business Suite

View all Oracle CVEs