Oracle Security Update – 06 October 2025

Oracle has released a critical security update to fix a zero-day vulnerability across Oracle E-Business Suite, versions 12.2.3-12.2.14.

The addressed vulnerability could allow the remote unauthenticated attacker to execute arbitrary code over HTTP and gain access to the affected product.

Oracle E-Business Suite Remote Code Execution Vulnerability (CVE-2025-61882):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

It should be highlighted that security researchers have discovered that the zeroday vulnerability “CVE-2025-61882” is actively exploited in the wild.

Vulnerabilities

CVE-2025-61882

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Oracle Security Update

References