CVE-2025-61882: Unauthenticated RCE in Oracle E-Business Suite BI Publisher

ISGroup Cybersecurity

Oracle E-Business Suite (EBS) is a comprehensive suite of integrated, global business applications that enables organizations to make better decisions, reduce costs, and increase performance. The Concurrent Processing component forms the core of the system, acting as a critical manager for background jobs and reports, making it essential for an organization’s financial, human resources, and supply chain operations.

This vulnerability represents a critical risk for any organization using the affected versions. An unauthenticated attacker with network access can achieve full Remote Code Execution (RCE), without the need for user interaction or privileges. The impact is a total compromise of the underlying server, with a CVSS score of 9.8 (Critical).

Given public reports on the exploitation of this vulnerability in targeted attacks against large organizations, including the healthcare and education sectors, this is not a theoretical threat. Any Oracle E-Business Suite instance exposed to the internet must be considered a high-priority target at immediate risk. The simplicity of exploitation, combined with the value of the data managed by EBS, makes this an ideal target for groups dedicated to ransomware and data extortion.

ProductOracle E-Business Suite
Date2025-12-06 12:26:41

Technical Summary

A critical unauthenticated remote code execution vulnerability exists within the BI Publisher integration functionality of the Oracle Concurrent Processing module. The root cause is a deserialization error (CWE-502: Deserialization of Untrusted Data) in how the application handles XML data streams sent to a specific service endpoint.

The technical attack chain is as follows:

  1. An attacker creates a malicious XML payload containing a serialized Java object.
  2. The attacker sends this payload via an HTTP POST request to an exposed BI Publisher endpoint, which does not require authentication.
  3. The application’s XML parser receives the stream and, without valid verification, passes it to a downstream function that deserializes the object.
  4. This process triggers a gadget chain within the application’s classpath, leading to the execution of arbitrary commands with the privileges of the Oracle application server user.
// Conceptual Example: Vulnerable Deserialization Logic
// The application directly deserializes an untrusted input stream from an HTTP request.
class BIPublisherRequestProcessor {
    public void handleRequest(InputStream untrustedStream) {
        // VULNERABLE: The ObjectInputStream reads and instantiates an object
        // from the attacker-controlled stream, leading to code execution.
        ObjectInputStream ois = new ObjectInputStream(untrustedStream);
        Object maliciousObject = ois.readObject();

        // ... further processing
    }
}

Attacker Capabilities: A successful exploit grants the attacker full control of the application server. This allows for arbitrary command execution, exfiltration of all critical business data (financial data, PII, etc.), manipulation of business processes, and the ability to move laterally within the corporate network.

Affected Versions:

  • Oracle E-Business Suite versions from 12.2.3 to 12.2.14 are vulnerable.

Patch Availability:

  • Oracle has released patches as part of its Critical Patch Update (CPU). All customers are advised to proceed with the update immediately.

Recommendations

  • Apply the patch immediately: Apply the Oracle Critical Patch Update (CPU) for Oracle E-Business Suite to all affected instances without delay. This is the only way to fully mitigate the vulnerability.

  • Mitigations:

    • If it is not possible to apply the patch immediately, restrict network access to the Oracle E-Business Suite application tier from all untrusted sources. In particular, block external access to the /OA_HTML/ directory if it is not necessary for business operations.
    • Implement a Web Application Firewall (WAF) with rules specifically designed to inspect and block Java deserialization attack patterns in HTTP POST messages.

  • Hunting and Monitoring:

    • Check web server access logs for HTTP POST requests to BI Publisher-related endpoints from external or unexpected IP addresses.
    • Monitor the Oracle application server for anomalous child processes started by the main Java process (e.g., sh, bash, cmd.exe, powershell.exe).
    • Analyze outbound network traffic from EBS application servers for connections to unknown or suspicious destinations, which could indicate C2 communications or data exfiltration.

  • Incident Response:

    • If a compromise is suspected, immediately isolate the affected server(s) from the network to prevent lateral movement.
    • Preserve all relevant logs (access logs, application logs, operating system logs) and create a forensic disk image for analysis.
    • Examine all application and database user accounts to verify unauthorized activity or privilege escalation.

  • Defense in Depth:

    • Ensure the EBS application is running using a service account with minimal privileges.
    • Implement robust network segmentation to control traffic between the application tier, the database tier, and the rest of the corporate network.
    • Verify that critical data is regularly backed up and that such backups are securely stored offline.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert