Oracle E-Business Suite是美国甲骨文(Oracle)公司的一套全面集成式的全球业务管理软件。该软件提供了客户关系管理、服务管理、财务管理等功能。 Oracle E-Business Suite的Oracle Configurator 12.2.3版本至12.2.14版本存在安全漏洞,该漏洞源于未经验证的攻击者可通过HTTP网络访问进行攻击,可能导致未经授权访问关键数据或完全访问所有Oracle Configurator可访问数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Oracle Corporation | Oracle Configurator | 12.2.3≤ 12.2.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Oracle Corporation | Oracle Configurator | 12.2.3 ~ 12.2.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2025-61884 | https://github.com/B1ack4sh/Blackash-CVE-2025-61884 | POC Details |
| 2 | None | https://github.com/shinyhunt/CVE-2025-61884 | POC Details |
| 3 | 🚨 CVE-2025-61884 — High-Risk Oracle EBS Configurator Info Disclosure | https://github.com/AshrafZaryouh/CVE-2025-61884-At-a-Glance | POC Details |
| 4 | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-61884.yaml | POC Details |
| 5 | CVE-2025-61884 | https://github.com/Ashwesker/Blackash-CVE-2025-61884 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet