Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Marc Lore says that AI will soon enable anyone open a restaurant

    May 6, 2026

    Altara secures $7M to bridge the data gap that’s slowing down physical sciences

    May 6, 2026

    India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality

    May 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Marc Lore says that AI will soon enable anyone open a restaurant
    • Altara secures $7M to bridge the data gap that’s slowing down physical sciences
    • India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality
    • OpenAI’s cozy partner Cerebras is on track for a blockbuster IPO
    • Katie Haun raises $1B for new venture funds
    • 5 days to get 50% off a second Disrupt 2026 pass
    • ‘This is fine’ creator says AI startup stole his art
    • Beyond Lovable and Mistral: 21 European startups to watch
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
    Security

    New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

    TechurzBy TechurzOctober 12, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 12, 2025Ravie LakshmananVulnerability / Threat Intelligence

    Oracle on Saturday issued a security alert warning of a fresh security flaw impacting its E-Business Suite that it said could allow unauthorized access to sensitive data.

    The vulnerability, tracked as CVE-2025-61884, carries a CVSS score of 7.5, indicating high severity. It affects versions from 12.2.3 through 12.2.14.

    “Easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Configurator,” according to a description of the flaw in the NIST’s National Vulnerability Database (NVD). “Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data.”

    In a standalone alert, Oracle said the flaw is remotely exploitable without requiring any authentication, making it crucial that users apply the update as soon as possible. The company, however, makes no mention of it being exploited in the wild.

    Oracle’s Chief Security Officer, Rob Duhart, pointed out that the vulnerability affects “some deployments” of E-Business Suite and that it could be weaponized to allow access to sensitive resources.

    The development comes shortly after Google Threat Intelligence Group (GTIG) and Mandiant disclosed that dozens of organizations may have been impacted following the zero-day exploitation of CVE-2025-61882 in Oracle’s E-Business Suite (EBS) software.

    The attacks have been found to leverage the vulnerability to trigger two different payload chains, dropping malware families like GOLDVEIN.JAVA, SAGEGIFT, SAGELEAF, and SAGEWAVE.

    While the tech giant did not specifically attribute the activity to a specific named threat actor or group, it’s believed that the attackers are orchestrated by a hacking group with ties to the Cl0p ransomware group.

    Access bug data EBusiness Hackers login Oracle Suite
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThese Bose headphones took my favorite AirPods Max battery feature – and did it even better
    Next Article Feeling lonely at work? You’re not alone – 5 ways to boost your team’s morale
    Techurz
    • Website

    Related Posts

    Opinion

    Altara secures $7M to bridge the data gap that’s slowing down physical sciences

    May 6, 2026
    Opinion

    After data breach, $10B valued startup Mercor is having a month

    April 9, 2026
    Opinion

    Nomadic raises $8.4 million to wrangle the data pouring off autonomous vehicles

    March 31, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Marc Lore says that AI will soon enable anyone open a restaurant

    May 6, 2026

    Altara secures $7M to bridge the data gap that’s slowing down physical sciences

    May 6, 2026

    India’s first GenAI unicorn shifts to cloud services as AI model ambitions face reality

    May 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.