Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

Authentication Bypass in Oracle E-Business Suite Oracle Configurator Runtime UI

IdentifiersCVE-2025-61884CWE-306

CVE-2025-61884 is an easily exploitable vulnerability in the Oracle Configurator Runtime UI component of Oracle E-Business Suite affecting supported versions 12.2.3 through 12.2.14. According to the provided content, the issue is a pre-authentication authentication bypass reachable over HTTP that allows a remote attacker with network access and no credentials to compromise Oracle Configurator and access sensitive data exposed through the Runtime UI. Publicly available details in the provided material do not identify the exact vulnerable function, endpoint, or code path. The documented impact is limited to confidentiality, with Oracle/NIST describing unauthorized access to critical data or complete access to all Oracle Configurator-accessible data.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to obtain unauthorized access to critical Oracle Configurator data, potentially including complete access to all data accessible through the affected component. Based on the supplied CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the primary impact is high confidentiality loss, with no confirmed integrity or availability impact in the provided content.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure of the Oracle Configurator Runtime UI by restricting HTTP network access to trusted administrative or application paths only, removing unnecessary internet exposure, and placing the application behind tightly controlled access controls and monitoring. Because the flaw is exploitable without authentication, defenders should prioritize compensating controls such as network segmentation, WAF/reverse-proxy filtering where feasible, aggressive log review for suspicious unauthenticated HTTP requests to Oracle Configurator, and incident hunting for possible data access or exfiltration. These are interim measures only; the provided content indicates patching is the required fix.

Remediation

Patch, then assume compromise.

Apply Oracle’s emergency security patch/update for CVE-2025-61884 for Oracle E-Business Suite as referenced in Oracle’s October 2025 security alert and Patch Availability Document. The provided content states affected versions are 12.2.3 through 12.2.14 and that Oracle strongly recommended prompt patching. Organizations should update all vulnerable Oracle E-Business Suite deployments running the Oracle Configurator Runtime UI component to the vendor-fixed version or patch level.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 5 candidates as fakes, detection scripts, or README-only repos.

VALID 0 / 5 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
OracleConfiguratorapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence12

Every observed campaign linking this CVE to a named adversary.

Associated malware6

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity135

Community discussion across Reddit, Mastodon, and other social sources.