References https://www.oracle.com/security-alerts/alert-cve-2025-61884.html https://nvd.nist.gov/vuln/detail/CVE-2025-61884 https://access.redhat.com/security/cve/cve-2025-61884 https://zeropath.com/blog/oracle-ebs-cve-2025-61884-summary https://www.tenable.com/plugins/nessus/270137 https://www.cve.org/CVERecord?id=CVE-2025-61884 https://socprime.com/blog/cve-2025-61884-vulnerability-in-oracle-ebs/ https://www.secpod.com/blog/cve-2025-61884-unauthenticated-data-exposure-in-oracle-e-business-suite/ https://www.helpnetsecurity.com/2025/10/12/another-remotely-exploitable-oracle-ebs-vulnerability-requires-your-attention-cve-2025-61884/ https://hadrian.io/blog/cve-2025-61884-high-severity-exposure-in-oracle-e-business-suite-ebs https://arcticwolf.com/resources/blog/cve-2025-61884/ https://thehackernews.com/2025/10/new-oracle-e-business-suite-bug-could.html
Related VulnerabilitiesPoCCVE-2026-35273: Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCEPoCCVE-2020-9314: Oracle iPlanet Web Server 7.0.x - Image InjectionPoCoracle-ebs-sqllog-exposure: Oracle EBS SQL Log - ExposurePoCCVE-2021-2135: Oracle WebLogic Server - Remote Code ExecutionOracle Identity Manager /iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl 命令执行漏洞(CVE-2025-61757)Oracle Identity Manager 访问控制不当漏洞PoCCVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication BypassOracle_E_Business 存在SSRF(CVE-2025-61884)(CVE-2025-61757)Oracle Identity Manager REST WebServices远程接管漏洞Oracle E-Business Suite 存在访问控制不当漏洞(CVE-2025-61884)