Known vulnerability record

CVE-2025-61884

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Stable IDcve:CVE-2025-61884Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

Keep the signals separate

CVSS severityhighScore 7.5 · source oracle
EPSS probability97.8%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-10-20
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-10-12
CVE modified
2026-08-04
KEV date added
2025-10-20
Dataset fetched
2026-08-21T03:55:00.955Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.