Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Meet Gizmo: A TikTok for interactive, vibe-coded mini apps

    February 4, 2026

    AI SRE Resolve AI confirms $125M raise, unicorn valuation

    February 4, 2026

    Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences

    February 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meet Gizmo: A TikTok for interactive, vibe-coded mini apps
    • AI SRE Resolve AI confirms $125M raise, unicorn valuation
    • Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences
    • Lunar Energy raises $232M to deploy home batteries that prop up the grid
    • ElevenLabs raises $500M from Sequoia at an $11 billion valuation
    • EXCLUSIVE: Positron raises $230M Series B to take on Nvidia’s AI chips
    • Epstein-linked longevity guru Peter Attia leaves David Protein, and his own startup ‘won’t comment’
    • India’s Varaha bags $20M to scale carbon removal from the Global South
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
    Security

    New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

    TechurzBy TechurzOctober 12, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 12, 2025Ravie LakshmananVulnerability / Threat Intelligence

    Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its E-Business Suite that it said could allow unauthorized access to sensitive data.

    The vulnerability, tracked as CVE-2025-61884, carries a CVSS score of 7.5, indicating high severity. It affects versions from 12.2.3 through 12.2.14.

    “Easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Configurator,” according to a description of the flaw in the NIST’s National Vulnerability Database (NVD). “Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.”

    In a standalone alert, Oracle said the flaw is remotely exploitable without requiring any authentication, making it crucial that users apply the update as soon as possible. The company, however, makes no mention of it being exploited in the wild.

    Oracle’s Chief Security Officer, Rob Duhart, pointed out that the vulnerability affects “some deployments” of E-Business Suite and that it could be weaponized to allow access to sensitive resources.

    The development comes shortly after Google Threat Intelligence Group (GTIG) and Mandiant disclosed that dozens of organizations may have been impacted following the zero-day exploitation of CVE-2025-61882 in Oracle’s E-Business Suite (EBS) software.

    The attacks have been found to leverage the vulnerability to trigger two different payload chains, dropping malware families like GOLDVEIN.JAVA, SAGEGIFT, SAGELEAF, and SAGEWAVE.

    While the tech giant did not specifically attribute the activity to a specific named threat actor or group, it’s believed that the attackers are orchestrated by a hacking group with ties to the Cl0p ransomware group.

    Access bug data EBusiness Hackers login Oracle Suite
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThese Bose headphones took my favorite AirPods Max battery feature – and did it even better
    Next Article Feeling lonely at work? You’re not alone – 5 ways to boost your team’s morale
    Techurz
    • Website

    Related Posts

    Opinion

    AI data labeler Handshake buys Cleanlab, an acquisition target of multiple others

    January 28, 2026
    Opinion

    Data security startup Cyera hits $9B valuation six months after being valued at $6B

    January 9, 2026
    Opinion

    MayimFlow wants to stop data center leaks before they happen

    December 28, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20251,147 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20251,147 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Our Picks

    Meet Gizmo: A TikTok for interactive, vibe-coded mini apps

    February 4, 2026

    AI SRE Resolve AI confirms $125M raise, unicorn valuation

    February 4, 2026

    Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences

    February 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.