Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
History

Tue, 21 Oct 2025 23:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 21 Oct 2025 12:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:configurator:*:*:*:*:*:*:*:*

Mon, 20 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle
Oracle configurator
Vendors & Products Oracle
Oracle configurator

Mon, 20 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-10-20T00:00:00+00:00', 'dueDate': '2025-11-10T00:00:00+00:00'}


Thu, 16 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-287
CWE-444
CWE-501
CWE-918
CWE-93
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 12 Oct 2025 03:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2025-10-12T02:34:51.603Z

Updated: 2025-10-21T22:45:16.617Z

Reserved: 2025-10-03T06:59:29.439Z

Link: CVE-2025-61884

cve-icon Vulnrichment

Updated: 2025-10-16T17:18:57.585Z

cve-icon NVD

Status : Modified

Published: 2025-10-12T03:15:34.720

Modified: 2025-10-21T23:17:08.960

Link: CVE-2025-61884

cve-icon Redhat

No data.