CVE-2025-61884
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 7 assertions
{"description":"Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.","lang":"en-US"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-444","description":"CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/3/descriptions/0
{"cweId":"CWE-93","description":"CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/2/descriptions/0
{"cweId":"CWE-501","description":"CWE-501 Trust Boundary Violation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/5/descriptions/0
{"cweId":"CWE-918","description":"CWE-918 Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/0/descriptions/0
{"cweId":"CWE-287","description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/4/descriptions/0
{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"Oracle Configurator","vendor":"Oracle Corporation","versions":[{"lessThanOrEqual":"12.2.14","status":"affected","version":"12.2.3","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
7 source assertions{"description":"Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.","lang":"en-US"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-444","description":"CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/3/descriptions/0
{"cweId":"CWE-93","description":"CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/2/descriptions/0
{"cweId":"CWE-501","description":"CWE-501 Trust Boundary Violation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/5/descriptions/0
{"cweId":"CWE-918","description":"CWE-918 Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/0/descriptions/0
{"cweId":"CWE-287","description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/4/descriptions/0
{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/1/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-918"],"dateAdded":"2025-10-20","dueDate":"2025-11-10","knownRansomwareCampaignUse":"Known","notes":"https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884","product":"E-Business Suite","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. Thi…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:3f2d7403e7b7e5842bf9edce269d4e594a90c013d2c9654f3311d8c250c3fcc1 · sha256:16acee8334e59e44… · /vulnerabilities/215Open source location →
{"cwes":["CWE-918"],"dateAdded":"2025-10-20","dueDate":"2025-11-10","knownRansomwareCampaignUse":"Known","notes":"https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884","product":"E-Business Suite","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. Thi…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:dd989320e532fa9ced27a537662b5006daea645e9bc6a1215a9ea6e0a492662f · sha256:635dff916c4092c0… · /vulnerabilities/218Open source location →
Source references
4 source assertions{"tags":["vendor-advisory"],"url":"https://blogs.oracle.com/security/post/apply-july-2025-cpu"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/references/1
{"tags":["exploit","technical-description","third-party-advisory"],"url":"https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/references/0
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61884"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/references/2
{"name":"Oracle Advisory","tags":["vendor-advisory"],"url":"https://www.oracle.com/security-alerts/alert-cve-2025-61884.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/references/0
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.