Input validation error in Oracle Concurrent Processing and Oracle E-Business Suite - CVE-2025-61882
Published: October 6, 2025 / Updated: January 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the BI Publisher Integration component. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Oracle E-Business Suite
How to mitigate CVE-2025-61882
Oracle E-Business Suite - update to 12.2.15
Links to Public Exploits and PoC-codes
- Exploit #12324 - Oracle E-Business Suite CVE-2025-61882 RCE (January 22, 2026)
- Exploit #12225 - CVE-2025-61882 (CVE-2025-61882: Oracle E-Business Suite RCE Scanner and Exploit ) (January 4, 2026)
- Exploit #12037 - CVE-2025-61882-Oracle-EBS (October 24, 2025)
- Exploit #12010 - CVE-2025-61882 (October 8, 2025)