---
id: CVE-2025-61882
title: >-
  Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business
  Suite (component: BI Publisher Integration)
summary: >-
  Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business
  Suite (component: BI Publisher Integration).  Supported versions that are
  affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows
  unauthenticated…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
vendor: oracle
product: concurrent_processing
affected:
  - 'concurrent_processing >= 12.2.3, <= 12.2.14'
published: '2025-10-05'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61882'
references:
  - url: 'https://www.oracle.com/security-alerts/alert-cve-2025-61882.html'
    label: secalert_us@oracle.com
  - url: 'https://blogs.oracle.com/security/post/apply-july-2025-cpu'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61882
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.crowdstrike.com/en-us/blog/crowdstrike-identifies-campaign-targeting-oracle-e-business-suite-zero-day-CVE-2025-61882/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99732
epssPercentile: 0.99953
kev: true
kevDateAdded: '2025-10-06'
kevDueDate: '2025-10-27'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-08-04T05:36:13.346Z'
exploits:
  github: 13
  githubRepos:
    - 'https://github.com/rxerium/CVE-2025-61882-CVE-2025-61884'
    - >-
      https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882
    - 'https://github.com/Sachinart/CVE-2025-61882'
  metasploit:
    - exploit/multi/http/oracle_ebs_cve_2025_61882_exploit_rce
  nuclei:
    - CVE-2025-61882
  checkedAt: '2026-09-10T03:03:49.995Z'
exploitAvailable: true
---

## Overview

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing.  Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

## Affected

- `concurrent_processing >= 12.2.3, <= 12.2.14`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
