CVE-2025-62481

CRITICAL EXPLOITED RANSOMWARE

Oracle Marketing 12.2.3-12.2.14 - Unauthenticated Authentication Bypass in Marketing Administration

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-62481 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns.

Description

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0009
EPSS Percentile 25.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-05-19
Ransomware Use Confirmed
CWE
CWE-306
Status published
Products (1)
oracle/marketing 12.2.3 - 12.2.14
Published Oct 21, 2025
Tracked Since Feb 18, 2026