---
id: CVE-2025-61884
title: >-
  Vulnerability in the Oracle Configurator product of Oracle E-Business Suite
  (component: Runtime UI)
summary: >-
  Vulnerability in the Oracle Configurator product of Oracle E-Business Suite
  (component: Runtime UI).  Supported versions that are affected are
  12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated
  attacker with network …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
  - CWE-93
  - CWE-287
  - CWE-444
  - CWE-501
  - CWE-918
vendor: oracle
product: configurator
affected:
  - 'configurator >= 12.2.3, <= 12.2.14'
published: '2025-10-12'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61884'
references:
  - url: 'https://www.oracle.com/security-alerts/alert-cve-2025-61884.html'
    label: secalert_us@oracle.com
  - url: 'https://blogs.oracle.com/security/post/apply-july-2025-cpu'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61884
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.95891
epssPercentile: 0.99873
kev: true
kevDateAdded: '2025-10-20'
kevDueDate: '2025-11-10'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-04T05:36:13.375Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/JrExploit/Blackash-CVE-2025-61884'
  nuclei:
    - CVE-2025-61884
  checkedAt: '2026-09-24T07:52:53.839Z'
exploitAvailable: true
---

## Overview

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

## Affected

- `configurator >= 12.2.3, <= 12.2.14`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
