[CIVN-2025-0260] Information Disclosure vulnerability in Oracle E-Business Suite
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Information Disclosure vulnerability in Oracle E-Business Suite
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Oracle E-Business Suite versions 12.2.3-12.2.14
Overview
A vulnerability has been reported in Oracle E-Business Suite, which could allow a remote attacker to access sensitive information on the targeted system.
Target Audience:
Large enterprises, industry sectors and IT departments using affected Oracle E-Business Suite (EBS).
Risk Assessment:
High risk of unauthorised access to sensitive data.
Impact Assessment:
Potential for unauthorised access and information disclosure.
Description
Oracle E-Business Suite (EBS) is an integrated set of enterprise applications designed to help organisations automate and manage core business functions such as finance, human resources, supply chain, and more. It supports global operations and can be deployed on-premises or in the cloud.
This vulnerability exists in the Oracle Configurator component (Runtime UI) of Oracle E-Business Suite and could be exploited without authentication over HTTP. The flaw allows a remote attacker to access sensitive data in Oracle Configurator.
Successful exploitation of this vulnerability could allow a remote attacker to access sensitive information on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.oracle.com/security-alerts/alert-cve-2025-61884.html
References
Oracle
https://www.oracle.com/security-alerts/alert-cve-2025-61884.html
CVE Name
CVE-2025-61884
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjyHyAACgkQ3jCgcSdc
ys8rbA/9G/QzRdFDDMSdcDrM4tO3F9eFx0QWfYO8ug3CE8A9pdVmc2SNgKjFG3Jm
hHJmGWPcg8zz4YQboNsNZqqm7n+imET8OMkjhQ1/Ml7wf5ral+OtPyOMsSqaKUi5
l5dLMRyI6X5cUg7IBxAoc7PLmHql8+PTzzuj2p5QmU2RP6KLg0J3EQ+7zu4mSjiW
qoNdNY9H/vz9Gwp8o6/vtaMmOClYseENsoCMHAmXWDQqBmPZA32TjGfHh2BHForW
WEx6V7gLPFZcSjjK8ByPr9ULN+eq6SQXOeO9rDvUDDl1NXXF7uKkE+r9GIZcd7y/
n2HjVNQANnh8AnHwNnp5GPJeeG4GjS3AXGcmK2iDyd7ROem2gP17U3xbUY6O5BlB
FJKYxp2x4OqwLPFaXrLMFd4QTDqECPZmTJM1eAhl6IFsmxdI7vwMs3CSBz6pxOfz
Rtoa5tuPUE5URD54QUHIWV8egaeIA4ziQNe70qCH4y7y2c80leZQRWZrQexsJ0SD
+lo4dQ8tCk5ukIHf5lw6R3+BvQSF1Zeejvcbys8gz/3U4uRZqQ6r4uUvf5K7ISWa
49xUGqOmrXhgF4/uh2q4sLXcdNnwBfFyiCVsW52Ts8iHs9YK+eK4OxKcbGbyAaNV
RJRj4QwJOgkuN9K27U3UAheA8//BSMXul7v6Xv/1t54hBBVsguo=
=nFeE
—–END PGP SIGNATURE—–