CVE-2025-61882

CRITICAL KEV RANSOMWARE NUCLEI

Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover

Title source: manual
STIX 2.1

Exploitation Summary

CVE-2025-61882 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 6, 2025, with confirmed use in ransomware campaigns. EIP tracks 17 public exploits from researchers including watchtowrlabs, iSee857, zerozenxlabs, including a Metasploit module exploits/multi/http/oracle_ebs_cve_2025_61882_exploit_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-61882, targeting Oracle E-Business Suite with a pre-authentication RCE chain. The exploit leverages CSRF token retrieval, HTTP request smuggling, and XSLT-based Java runtime execution to achieve remote code execution.

Description

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (17)

github WORKING POC 54 stars
by watchtowrlabs · pythonremote
https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

This repository contains a functional exploit for CVE-2025-61882, targeting Oracle E-Business Suite with a pre-authentication RCE chain. The exploit leverages CSRF token retrieval, HTTP request smuggling, and XSLT-based Java runtime execution to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle E-Business Suite versions 12.2.3-12.2.14
No auth needed
Prerequisites: Network access to the target Oracle E-Business Suite instance · Python environment with required libraries (requests, argparse)
devstral-2 · analyzed Feb 19, 2026 Full analysis →
github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/Oracle_E_Business-CVE-2025-61882-RCE.py

The repository contains a functional exploit PoC for CVE-2026-22812, targeting OpenCode for remote command execution (RCE). The script establishes a session, then sends a crafted JSON payload to execute the 'id' command, verifying RCE by checking for 'uid=' and 'gid=' in the response.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OpenCode (version not specified)
No auth needed
Prerequisites: Network access to the target · OpenCode service running and accessible
devstral-2 · analyzed Feb 27, 2026 Full analysis →
github WORKING POC 19 stars
by zerozenxlabs · pythonremote
https://github.com/zerozenxlabs/CVE-2025-61882-Oracle-EBS

This repository contains a functional exploit for CVE-2025-61882, targeting Oracle E-Business Suite. The exploit leverages SSRF and CRLF injection to achieve remote code execution (RCE) by crafting malicious HTTP requests and using a malicious server to deliver payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle E-Business Suite
No auth needed
Prerequisites: Network access to the target Oracle E-Business Suite instance · A server controlled by the attacker to host malicious payloads
devstral-2 · analyzed Feb 19, 2026 Full analysis →
github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-61882

This repository contains a functional SQL injection exploit for WordPress Quiz Maker (CVE-2025-10042). The Python script demonstrates time-based blind SQLi via crafted HTTP headers, extracting admin credentials and password hashes.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WordPress Quiz Maker <= 6.7.0.56
No auth needed
Prerequisites: target WordPress URL · path to quiz page · vulnerable header (default: X-Forwarded-For)
devstral-2 · analyzed Feb 27, 2026 Full analysis →
github WRITEUP 8 stars
by AdityaBhatt3010 · pythonpoc
https://github.com/AdityaBhatt3010/CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit

This repository provides a detailed technical analysis and detection guidance for CVE-2025-61882, a pre-authentication RCE vulnerability in Oracle E-Business Suite (versions 12.2.3–12.2.14). It includes IOCs, detection rules for Splunk/Elastic, and a safe Python script for log analysis.

Classification
Writeup 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle E-Business Suite 12.2.3–12.2.14
No auth needed
Prerequisites: Web-facing Oracle E-Business Suite instance · Network access to vulnerable endpoints
devstral-2 · analyzed Feb 19, 2026 Full analysis →
github WRITEUP 7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-61882.md

The repository contains detailed technical writeups for multiple CVEs, including command injection, XXE, SQLi, and RCE vulnerabilities. Each writeup provides vulnerability overviews, proof-of-concept details, and mitigation recommendations.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Various (e.g., account_mgr.cgi, Ivanti Connect Secure, Zabbix, Check Point VPN, Bricks Builder)
No auth needed
Prerequisites: Access to vulnerable endpoints · Basic understanding of exploit techniques
devstral-2 · analyzed Feb 27, 2026 Full analysis →
github WORKING POC 7 stars
by Sachinart · pythonremote
https://github.com/Sachinart/CVE-2025-61882

This repository contains a functional multi-threaded scanner and exploit for CVE-2025-61882, targeting Oracle E-Business Suite. The exploit leverages HTTP request smuggling and XSL payload delivery to achieve unauthenticated remote code execution (RCE).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle E-Business Suite
No auth needed
Prerequisites: Target must be running vulnerable Oracle E-Business Suite · Attacker must have network access to the target · Attacker must have a VPS/attacker IP to receive callbacks
devstral-2 · analyzed Feb 19, 2026 Full analysis →
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-61882

The repository contains functional exploit code for multiple CVEs, including authentication bypass vulnerabilities in TOTOLINK devices and a scanner for Fortinet SSL VPN (CVE-2024-21762). The PoCs demonstrate the vulnerabilities with clear technical details and executable scripts.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: TOTOLINK LR350, TOTOLINK T6, Fortinet SSL VPN
No auth needed
Prerequisites: network access to the target device
devstral-2 · analyzed Feb 27, 2026 Full analysis →
github SCANNER 2 stars
by BattalionX · luapoc
https://github.com/BattalionX/http-oracle-ebs-cve-2025-61882.nse

This repository contains an NSE script for detecting Oracle E-Business Suite vulnerability CVE-2025-61882. It performs multi-tier checks including fingerprinting, version checks, and optional active probing for high-confidence detection.

Classification
Scanner 80%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Oracle E-Business Suite
No auth needed
Prerequisites: Network access to the target Oracle E-Business Suite instance
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC 1 stars
by George0Papasotiriou · poc
https://github.com/George0Papasotiriou/CVE-2025-61882-Oracle-BI-Publisher-RCE

This PoC demonstrates a remote code execution vulnerability in Oracle BI Publisher via insecure deserialization. It includes a Java exploit that generates a serialized payload and a bash script to simulate sending it to the vulnerable endpoint.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle BI Publisher versions 12.2.1.4.0, 12.2.1.3.0
No auth needed
Prerequisites: Network access to the vulnerable Oracle BI Publisher server · Ability to send crafted serialized data to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC 1 stars
by GhoStZA-debug · infoleak
https://github.com/GhoStZA-debug/CVE-2025-61882

This repository contains functional exploit code for CVE-2025-61882, an unauthenticated remote code execution vulnerability in Oracle E-Business Suite (EBS) BI Publisher. The exploit leverages server-side template injection via crafted XSLT/XML payloads, demonstrating pre-auth RCE through SSRF and CRLF injection techniques.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle E-Business Suite (EBS) 12.2.x
No auth needed
Prerequisites: Network access to vulnerable EBS instance · Ability to host malicious XSLT payload on attacker-controlled server
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec STUB
by NetVanguard-cmd · poc
https://github.com/NetVanguard-cmd/CVE-2025-61882

The repository contains only a minimal README with a CVE identifier and no functional exploit code or technical details. It appears to be a placeholder or stub.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Apr 19, 2026 Full analysis →
nomisec SUSPICIOUS
by siddu7575 · poc
https://github.com/siddu7575/CVE-2025-61882-CVE-2025-61884

The repository claims to provide a tool for detecting Oracle vulnerabilities (CVE-2025-61882 and CVE-2025-61884) but only contains a README with download links to a ZIP file. No actual exploit code or technical details are provided, raising suspicion.

Classification
Suspicious 80%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Oracle (unspecified version)
No auth needed
Prerequisites: none specified
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by sid-203 · poc
https://github.com/sid-203/Enterprise-Information-Security-Risk-Assessment-Oracle-E-Business-Suite-Case-Study

This repository is a comprehensive academic writeup analyzing GDPR compliance, security frameworks, and a case study on the Oracle E-Business Suite breach involving CVE-2025-61882. It does not contain exploit code but provides a detailed incident response analysis.

Classification
Writeup 100%
Attack Type
None
Complexity
None
Reliability
None
Target: Oracle E-Business Suite (CVE-2025-61882)
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER
by Zhert-lab · poc
https://github.com/Zhert-lab/CVE-2025-61882-CVE-2025-61884

This repository provides a Nuclei template for detecting Oracle E-Business Suite instances vulnerable to CVE-2025-61882 by checking the Last-Modified header date. It also includes a detection script for CVE-2025-61884.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle E-Business Suite
No auth needed
Prerequisites: Nuclei installed · Target URL or IP
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC
by MindflareX · pythonpoc
https://github.com/MindflareX/CVE-2025-61882-POC

This repository contains a functional exploit for CVE-2025-61882, a critical pre-authentication RCE vulnerability in Oracle E-Business Suite. The exploit chains SSRF, CRLF injection, HTTP smuggling, authentication bypass, and XSLT injection to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Oracle E-Business Suite 12.2.3 - 12.2.14
No auth needed
Prerequisites: Python 3.7+ · Network connectivity to target · Netcat or similar listener
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by watchTowr (Sonny, Sina Kheirkhah, Jake Knott), Mathieu Dupas · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/oracle_ebs_cve_2025_61882_exploit_rce.rb

This Metasploit module exploits CVE-2025-61882 in Oracle E-Business Suite by chaining SSRF, Path Traversal, HTTP request smuggling, and XSLT injection to achieve remote code execution. It hosts a malicious XSL file that the target fetches and processes, leading to an interactive shell session.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Oracle E-Business Suite 12.2.3-12.2.14
No auth needed
Prerequisites: Network access to the target Oracle E-Business Suite instance · Target must be running a vulnerable version (12.2.3-12.2.14)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Execution
CRITICALVERIFIEDby testanull,watchtowr,DhiyaneshDk,pussycat0x
FOFA: title="E-Business Suite"

Scores

CVSS v3 9.8
EPSS 0.9086
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2025-10-06
VulnCheck KEV 2025-10-04
ENISA EUVD EUVD-2025-32142
Ransomware Use Confirmed
CWE
CWE-287
Status published
Products (1)
oracle/concurrent_processing 12.2.3 - 12.2.14
Published Oct 05, 2025
KEV Added Oct 06, 2025
Tracked Since Feb 18, 2026