References https://www.oracle.com/security-alerts/alert-cve-2025-61882.html https://nvd.nist.gov/vuln/detail/CVE-2025-61882 https://www.cve.org/CVERecord?id=CVE-2025-61882 https://www.cnblogs.com/yangykaifa/p/19458595 https://cloud.tencent.com/developer/article/2629052 https://www.tenablecloud.cn/plugins/nessus/266696 https://www.crowdstrike.com/en-us/blog/crowdstrike-identifies-campaign-targeting-oracle-e-business-suite-zero-day-CVE-2025-61882/ https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882 https://www.picussecurity.com/resource/blog/oracle-ebs-cve-2025-61882-vulnerability https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/
Related VulnerabilitiesPoCCVE-2026-13001: Podlove Podcast Publisher <= 4.5.1 - Arbitrary File UploadPoCCVE-2026-35273: Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCEPoCCVE-2020-9314: Oracle iPlanet Web Server 7.0.x - Image InjectionPoCoracle-ebs-sqllog-exposure: Oracle EBS SQL Log - ExposurePoCCVE-2021-2135: Oracle WebLogic Server - Remote Code ExecutionOracle Identity Manager /iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl 命令执行漏洞(CVE-2025-61757)Oracle Identity Manager 访问控制不当漏洞PoCCVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication BypassOracle_E_Business 存在SSRF(CVE-2025-61884)(CVE-2025-61757)Oracle Identity Manager REST WebServices远程接管漏洞(CVE-2025-61884) Oracle配置器运行时UI未授权访问漏洞