InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: New bug in Oracle E-Business Suite could allow hackers to access data without logging in
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > New bug in Oracle E-Business Suite could allow hackers to access data without logging in
Technology

New bug in Oracle E-Business Suite could allow hackers to access data without logging in

October 12, 2025 2 Min Read
Share
New bug in Oracle E-Business Suite could allow hackers to access data without logging in
SHARE

Oracle on Saturday issued a security alert warning of new security flaws affecting its E-Business Suite that could potentially allow unauthorized access to sensitive data.

Vulnerabilities are tracked as follows CVE-2025-61884the CVSS score is 7.5, indicating high severity. Affected versions are 12.2.3 to 12.2.14.

“Easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Configurator,” according to the flaw description in NIST’s National Vulnerability Database (NVD). “Successful attacks of this vulnerability could result in unauthorized access to critical data or complete access to all data accessible by Oracle Configurator.”

Oracle said in a separate warning that the flaw can be exploited remotely with no authentication required and it is important for users to apply the update as soon as possible. However, the company did not mention that it was actually being exploited.

Rob Duhart, Oracle’s chief security officer, said the vulnerability affects “some deployments” of E-Business Suite and could be weaponized to gain access to sensitive resources.

This development comes on the heels of Google Threat Intelligence Group (GTIG) and Mandiant revealing that dozens of organizations may have been affected by a zero-day exploit of CVE-2025-61882 in Oracle’s E-Business Suite (EBS) software.

This attack is known to leverage this vulnerability to trigger two different payload chains to drop malware families including GOLDVEIN.JAVA, SAGEGIFT, SAGELEAF, and SAGEWAVE.

The tech giant did not explicitly attribute this activity to any specific named attacker or group, but the attackers are believed to be orchestrated by a group of hackers with ties to the Cl0p ransomware group.

See also  New Coldriver Malware Campaign joins BO Team and Bearlyfy in a Russian-focused cyberattack
Share This Article
Twitter Copy Link
Previous Article Modern Warfare RTS Broken Arrow finally begins the battle for faction balance Modern Warfare RTS Broken Arrow finally begins the battle for faction balance
Next Article Vance warns of 'deeper' cuts in federal workforce as government shutdown enters 12th day Vance warns of ‘deeper’ cuts in federal workforce as government shutdown enters 12th day

Latest News

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

A maximum severity security flaw has been disclosed in React…

December 3, 2025
India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India's Department of Telecommunications (DoT) has directed app-based telecom service…

December 2, 2025
India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India's Ministry of Telecommunications has reportedly asked major mobile device…

December 1, 2025
CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

CISA adds actively exploited XSS bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated…

November 30, 2025
North Korean hackers deploy 197 npm packages to spread latest OtterCookie malware

North Korean hackers deploy 197 npm packages to spread latest OtterCookie malware

The North Korean threat actors behind the Contagious Interview campaign…

November 29, 2025

You Might Also Like

ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability
Technology

ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability

3 Min Read
Russian IT Network
Technology

Chinese threat group Jewelbug secretly infiltrated Russian IT networks for months

5 Min Read
New TEE.Fail side-channel attack extracts secrets from Intel and AMD DDR5 secure enclaves
Technology

New TEE.Fail side-channel attack extracts secrets from Intel and AMD DDR5 secure enclaves

4 Min Read
China-linked Plugx and BookWorm Malware Attack Targets Asia Telecom and ASEAN Network
Technology

China-linked Plugx and BookWorm Malware Attack Targets Asia Telecom and ASEAN Network

5 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?