Back to News
Market Impact: 0.65

New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

ORCLGOOGLGOOG
Technology & InnovationCybersecurity & Data Privacy
New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

Oracle has issued a security alert regarding a new high-severity vulnerability (CVE-2025-61884, CVSS 7.5) in its E-Business Suite, affecting versions 12.2.3 through 12.2.14, which allows unauthenticated remote access to sensitive data. This development follows recent disclosures by Google and Mandiant of zero-day exploitation of a *separate* EBS flaw (CVE-2025-61882) by a hacking group potentially linked to Cl0p ransomware, which deployed malware like GOLDVEIN.JAVA. While the newly identified flaw is not yet exploited in the wild, the ongoing security vulnerabilities underscore significant operational and data security risks for Oracle EBS users.

Analysis

Oracle has issued a critical security alert concerning a new high-severity vulnerability, CVE-2025-61884 (CVSS 7.5), within its E-Business Suite (EBS) affecting versions 12.2.3 through 12.2.14. This flaw allows unauthenticated attackers with network access via HTTP to compromise Oracle Configurator, potentially leading to unauthorized access to critical or all accessible data. While Oracle states this specific vulnerability is not yet exploited in the wild, it underscores significant data security risks for EBS users. This latest alert follows closely on the heels of recent disclosures by Google Threat Intelligence Group and Mandiant regarding the zero-day exploitation of a separate EBS vulnerability, CVE-2025-61882. That previous attack impacted dozens of organizations, deploying malware families like GOLDVEIN.JAVA and SAGEGIFT, and is believed to be orchestrated by a hacking group linked to Cl0p ransomware. The recurrence of high-profile security flaws in EBS raises concerns about the platform's overall security posture. The continuous stream of critical vulnerabilities in Oracle's E-Business Suite presents operational and reputational risks for Oracle (ORCL) and its extensive enterprise client base. While Oracle recommends immediate patching, the ease of exploitation and the unauthenticated nature of the new flaw, coupled with the prior zero-day attacks, could erode client confidence and potentially impact future software sales or renewals. This situation highlights ongoing cybersecurity challenges for a core enterprise software product.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

strongly negative

Sentiment Score

-0.75

Ticker Sentiment

GOOG0.00
GOOGL0.00
ORCL-0.80

Key Decisions for Investors

  • Monitor Oracle's (ORCL) enterprise client retention and new sales pipeline for any impact from recurring security concerns
  • Evaluate the cybersecurity posture and patching diligence of companies within your portfolio that are significant users of Oracle E-Business Suite
  • Watch for any confirmed exploitation of CVE-2025-61884 in the wild, as this would significantly escalate the financial and operational risks for affected organizations and Oracle itself