Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
1

Preserved source conflicts

No provider value was silently selected as the winner.

cwe · 7 assertions

{"description":"Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.","lang":"en-US"}

  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/problemTypes/0/descriptions/0

{"cweId":"CWE-444","description":"CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","lang":"en","type":"CWE"}

  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/3/descriptions/0

{"cweId":"CWE-93","description":"CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}

  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/2/descriptions/0

{"cweId":"CWE-501","description":"CWE-501 Trust Boundary Violation","lang":"en","type":"CWE"}

  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/5/descriptions/0

{"cweId":"CWE-918","description":"CWE-918 Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}

  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/0/descriptions/0

{"cweId":"CWE-287","description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}

  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/4/descriptions/0

{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}

  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/1/descriptions/0

Affected products and versions

1 source assertion
{"product":"Oracle Configurator","vendor":"Oracle Corporation","versions":[{"lessThanOrEqual":"12.2.14","status":"affected","version":"12.2.3","versionType":"custom"}]}
  • cve_program_cvelist_v5affected
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/affected/0

Provider-owned CVSS observations

1 source assertion
{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
  • cve_program_cvelist_v5cvss
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/metrics/0/cvssV3_1

CWE assertions

7 source assertions
{"description":"Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.","lang":"en-US"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-444","description":"CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/3/descriptions/0
{"cweId":"CWE-93","description":"CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/2/descriptions/0
{"cweId":"CWE-501","description":"CWE-501 Trust Boundary Violation","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/5/descriptions/0
{"cweId":"CWE-918","description":"CWE-918 Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/0/descriptions/0
{"cweId":"CWE-287","description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/4/descriptions/0
{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/problemTypes/1/descriptions/0

Known exploitation assertions

2 source assertions
{"cwes":["CWE-918"],"dateAdded":"2025-10-20","dueDate":"2025-11-10","knownRansomwareCampaignUse":"Known","notes":"https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884","product":"E-Business Suite","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. Thi…
  • cisa_kev_jsonknown_exploited
    urn:baitaphish:normalized-source-record:v2:3f2d7403e7b7e5842bf9edce269d4e594a90c013d2c9654f3311d8c250c3fcc1 · sha256:16acee8334e59e44… · /vulnerabilities/215
    Open source location →
{"cwes":["CWE-918"],"dateAdded":"2025-10-20","dueDate":"2025-11-10","knownRansomwareCampaignUse":"Known","notes":"https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884","product":"E-Business Suite","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. Thi…
  • cisa_kev_jsonknown_exploited
    urn:baitaphish:normalized-source-record:v2:dd989320e532fa9ced27a537662b5006daea645e9bc6a1215a9ea6e0a492662f · sha256:635dff916c4092c0… · /vulnerabilities/218
    Open source location →

Source references

4 source assertions
{"tags":["vendor-advisory"],"url":"https://blogs.oracle.com/security/post/apply-july-2025-cpu"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/references/1
{"tags":["exploit","technical-description","third-party-advisory"],"url":"https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/references/0
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61884"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/adp/0/references/2
{"name":"Oracle Advisory","tags":["vendor-advisory"],"url":"https://www.oracle.com/security-alerts/alert-cve-2025-61884.html"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:dc195d22dddcdd76e5ec6d954e25e683ce67f3ca2ced0fa3ea731c75f783b2e7 · sha256:736c6226b4396c49… · /containers/cna/references/0

Attribution and limitations

  • CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
  • CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →

Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.