#VU116601 Input validation error in Oracle E-Business Suite and Oracle Concurrent Processing - CVE-2025-61882
Published: October 6, 2025 / Updated: January 22, 2026
Oracle E-Business Suite
Oracle Concurrent Processing
Oracle
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the BI Publisher Integration component. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.