Oracle E-Business Suite was recently found to be vulnerable to a critical security flaw, CVE-2025-61882, which has been actively exploited in the wild. Oracle published a security bulletin disclosing the vulnerability, providing a patch, and sharing indicators of compromise observed during incident response. Attackers leveraged a Python-based exploit script, referred to as 'exp.py', which automates the exploitation process by interacting with specific endpoints in Oracle E-Business Suite. The script initiates by sending a GET request to '/OA_HTML/runforms.jsp' to determine the internal host, followed by a POST request to '/OA_HTML/JavaScriptServlet' to retrieve a CSRF token required for further exploitation. The final exploit request is sent to '/OA_HTML/configurator/UiServlet', with a crafted payload designed to trigger the vulnerability.
Analysis of attack logs reveals that the initial exploitation is followed by the dropping of malicious template files onto the target system. These templates are then activated by previewing them, which triggers further malicious activity. Apache logs from compromised systems show a sequence of GET and POST requests to endpoints such as '/OA_HTML/OA.jsp?page=/oracle/apps/xdo/oa/template/webui/TemplateCopyPG' and '/OA_HTML/OA.jsp?page=/oracle/apps/xdo/oa/template/webui/TemplateFileAddPG', indicating the deployment and activation of these templates. Two distinct types of malicious templates have been identified. The first type contacts a hardcoded command-and-control (C2) IP address and executes arbitrary Java code within the context of the Oracle WebLogic server, allowing attackers to maintain persistence without dropping additional files to disk. This template retrieves the HTTP response object, sends data back to the attacker, and establishes a connection to the C2 server using a custom protocol string, then loads and executes a Java class received from the C2 server after decrypting it.
The second template type embeds a Java class file directly within the template, which is decoded and executed upon activation. This template installs a backdoor that enables attackers to send specially crafted POST requests to a specific endpoint ('/support/state/content/destination./navId.1/navvSetId.iHelp/') to execute arbitrary Java code remotely. Both template types use base64 encoding to obfuscate their payloads, which are decoded and executed in memory, making detection and forensic analysis more challenging. The exploitation chain demonstrates a sophisticated understanding of Oracle E-Business Suite internals and leverages multiple stages to achieve code execution and persistence.
Oracle's response included the release of a patch and detailed indicators of compromise, such as specific HTTP request patterns and file artifacts, to aid defenders in identifying affected systems. Security researchers have provided in-depth technical analyses of the exploit script and the malicious templates, highlighting the importance of monitoring for unusual template file activity and suspicious HTTP requests in Oracle E-Business Suite environments. The attack underscores the critical need for organizations to apply security patches promptly and to monitor for signs of exploitation, especially in widely deployed enterprise applications like Oracle E-Business Suite. The use of in-memory execution and custom C2 protocols further complicates detection and response efforts. Organizations are advised to review Oracle's security bulletin, apply the provided patch, and search for the published indicators of compromise to ensure their environments are not affected by this active threat.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
On 2025-10-06, an independent researcher published a technical blog post titled "It's Java All The Way Down," apparently related to the same Oracle E-Business Suite exploitation topic. This represents additional public technical analysis emerging around the suspected CVE-2025-61882 exploit activity.
On 2025-10-06, SANS ISC published a quick analysis of a suspected exploit script targeting Oracle E-Business Suite and referencing CVE-2025-61882. The post indicates technical details of the suspected exploitation activity were being examined publicly.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.