Exploited Known exploited (KEV) Ransomware use CVE-2025-61882

Oracle E-Business Suite unspecified vulnerability (CVE-2025-61882) — listed on the fact of exploitation while the class of flaw is undetermined

Oracle E-Business Suite Added to KEV Oct 6, 2025 Federal remediation due 2025-10-27

An unspecified vulnerability in the core business system Oracle E-Business Suite. Both the name and the description say unspecified, and the records this site holds carry no class of flaw. It appears in the catalog nonetheless because exploitation was confirmed.

Key facts

  • CVE IDCVE-2025-61882
  • Affected (vendor / product)Oracle E-Business Suite
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2025-10-27 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected product is Oracle E-Business Suite, with the name given as an unspecified vulnerability and no class recorded.
  • The catalog collects what has been confirmed as actually exploited, so an entry can appear with the class undetermined.
  • It sits in a named component, and an unauthenticated party with network access via HTTP is described as able to compromise a processing component.
  • Successful attacks can result in takeover of that processing.
  • Across the records this site holds as of 2026-09-04, business platform entries with known ransomware use number 32.

1Listed without a class

Entries in the catalog normally carry a classification for the flaw, and this site organizes its articles by those classes. This entry carries none, and the vulnerability name itself reads unspecified.

An ordinary entryAn entry like this one
A class of flaw is assignedNo class is recorded
The name conveys the nature of the flawThe name says unspecified
It can be understood beside similar flawsIt can only be handled on its own

This is not a gap in the record. The catalog collects what has been confirmed as actually exploited. The fact of exploitation comes first, and detailed classification of the mechanism can come later. That a class is undetermined and that there is no danger are different things.

2What is known

  1. 1WhereA component described as BI Publisher Integration
  2. 2RequirementNetwork access via HTTP; no authentication needed
  3. 3EffectA particular processing component may be compromised
  4. 4ResultSuccess can lead to takeover of that processing

Even with the class unspecified, where it sits, what is required and what may follow are all recorded. What defence needs is those, rather than the classification itself. A class helps in understanding problems across cases; handling one case needs the location, the conditions and the effect.

3Where a core business system sits

Business platform grouping across the records this site holds as of 2026-09-0432 unpublished entries with known ransomware useBehind boundary devices at 59
Due date here21 daysAdded October 6, 2025, due October 27
Other entries for the same productPresent in the records this site holds as of 2026-09-04From the same period

Core business systems carry accounting, purchasing, inventory and personnel. Systems of this kind are hard to schedule downtime for, so updates tend to be deferred, while the range of information they hold is wide. Across the records this site holds as of 2026-09-04, 32 unpublished entries in this grouping carry known ransomware use.

4What unspecified means in practice

Without a class, there is no handle for looking sideways to find whether similar flaws exist elsewhere. Put the other way, an entry like this can only be handled individually, and following vendor guidance carries more weight than usual.

Why it matters

An entry without a class offers no handle for finding similar flaws elsewhere and can only be handled individually. Combined with core systems being hard to take down for updates, the response burden rises.

FAQ

Does an unspecified class mean lower risk?
No. The catalog collects what has been confirmed as actually exploited. A class being undetermined and there being no danger are different things.
Can it be handled without a class?
Handling one case needs the location, the conditions and the effect. A class is useful for understanding problems across cases.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Core business systems#Oracle
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.