Oracle E-Business Suite unspecified vulnerability (CVE-2025-61882) — listed on the fact of exploitation while the class of flaw is undetermined
An unspecified vulnerability in the core business system Oracle E-Business Suite. Both the name and the description say unspecified, and the records this site holds carry no class of flaw. It appears in the catalog nonetheless because exploitation was confirmed.
Key facts
- CVE IDCVE-2025-61882
- Affected (vendor / product)Oracle E-Business Suite
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2025-10-27 (U.S. federal civilian agencies, BOD 22-01)
Key points
- The affected product is Oracle E-Business Suite, with the name given as an unspecified vulnerability and no class recorded.
- The catalog collects what has been confirmed as actually exploited, so an entry can appear with the class undetermined.
- It sits in a named component, and an unauthenticated party with network access via HTTP is described as able to compromise a processing component.
- Successful attacks can result in takeover of that processing.
- Across the records this site holds as of 2026-09-04, business platform entries with known ransomware use number 32.
1Listed without a class
Entries in the catalog normally carry a classification for the flaw, and this site organizes its articles by those classes. This entry carries none, and the vulnerability name itself reads unspecified.
This is not a gap in the record. The catalog collects what has been confirmed as actually exploited. The fact of exploitation comes first, and detailed classification of the mechanism can come later. That a class is undetermined and that there is no danger are different things.
2What is known
- 1WhereA component described as BI Publisher Integration
- 2RequirementNetwork access via HTTP; no authentication needed
- 3EffectA particular processing component may be compromised
- 4ResultSuccess can lead to takeover of that processing
Even with the class unspecified, where it sits, what is required and what may follow are all recorded. What defence needs is those, rather than the classification itself. A class helps in understanding problems across cases; handling one case needs the location, the conditions and the effect.
3Where a core business system sits
Core business systems carry accounting, purchasing, inventory and personnel. Systems of this kind are hard to schedule downtime for, so updates tend to be deferred, while the range of information they hold is wide. Across the records this site holds as of 2026-09-04, 32 unpublished entries in this grouping carry known ransomware use.
4What unspecified means in practice
Without a class, there is no handle for looking sideways to find whether similar flaws exist elsewhere. Put the other way, an entry like this can only be handled individually, and following vendor guidance carries more weight than usual.
Why it matters
An entry without a class offers no handle for finding similar flaws elsewhere and can only be handled individually. Combined with core systems being hard to take down for updates, the response burden rises.
FAQ
Does an unspecified class mean lower risk?
Can it be handled without a class?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).