By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
Computing

New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

News Room
Last updated: 2025/10/12 at 1:54 PM
News Room Published 12 October 2025
Share
New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
SHARE

Oct 12, 2025Ravie LakshmananVulnerability / Threat Intelligence

Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its E-Business Suite that it said could allow unauthorized access to sensitive data.

The vulnerability, tracked as CVE-2025-61884, carries a CVSS score of 7.5, indicating high severity. It affects versions from 12.2.3 through 12.2.14.

“Easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Configurator,” according to a description of the flaw in the NIST’s National Vulnerability Database (NVD). “Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.”

In a standalone alert, Oracle said the flaw is remotely exploitable without requiring any authentication, making it crucial that users apply the update as soon as possible. The company, however, makes no mention of it being exploited in the wild.

CIS Build Kits

Oracle’s Chief Security Officer, Rob Duhart, pointed out that the vulnerability affects “some deployments” of E-Business Suite and that it could be weaponized to allow access to sensitive resources.

The development comes shortly after Google Threat Intelligence Group (GTIG) and Mandiant disclosed that dozens of organizations may have been impacted following the zero-day exploitation of CVE-2025-61882 in Oracle’s E-Business Suite (EBS) software.

The attacks have been found to leverage the vulnerability to trigger two different payload chains, dropping malware families like GOLDVEIN.JAVA, SAGEGIFT, SAGELEAF, and SAGEWAVE.

While the tech giant did not specifically attribute the activity to a specific named threat actor or group, it’s believed that the attackers are orchestrated by a hacking group with ties to the Cl0p ransomware group.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article What Does The ‘C’ Actually Mean On A USB-C Port? – BGR What Does The ‘C’ Actually Mean On A USB-C Port? – BGR
Next Article Trump administration wields X like a weapon Trump administration wields X like a weapon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

2026 is going to be RGB Mini LED vs OLED slugfest
2026 is going to be RGB Mini LED vs OLED slugfest
Gadget
Not Happy About Firefox Becoming an AI Browser? New CEO Promises AI Kill Switch
Not Happy About Firefox Becoming an AI Browser? New CEO Promises AI Kill Switch
News
Top Winter Offers You Shouldn’t Miss
Top Winter Offers You Shouldn’t Miss
Mobile
Android 16’s final quarterly beta is here for Pixel phones
Android 16’s final quarterly beta is here for Pixel phones
News

You Might also Like

Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence
Computing

Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence

6 Min Read
The Best Canva Fonts for Printable Products
Computing

The Best Canva Fonts for Printable Products

20 Min Read
How To Create Pinterest Templates That Actually Rank
Computing

How To Create Pinterest Templates That Actually Rank

18 Min Read
GotaTun Open-Source Rust WireGuard Implementation Announced By Mullvad
Computing

GotaTun Open-Source Rust WireGuard Implementation Announced By Mullvad

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?