{"id":21361,"date":"2025-10-13T21:45:24","date_gmt":"2025-10-13T21:45:24","guid":{"rendered":"http:\/\/localhost\/?p=21361"},"modified":"2025-10-13T21:45:24","modified_gmt":"2025-10-13T21:45:24","slug":"cve-2025-61882-imperva-customers-protected-against-critical-oracle-ebs-zero-day-rce","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=21361","title":{"rendered":"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-14T02:05:08&#8243;,&#8221;description&#8221;:&#8221;_TL;DR: In early October 2025, Oracle released an emergency security alert addressing CVE-2025-61882, a high-severity unauthenticated remote code execution (RCE) vulnerability in the Concurrent Processing \/ BI Publisher Integration component of Oracle E-Business Suite (EBS) versions 12.2.3 through 12.2.14. Multiple threat actors (most prominently Cl0p and related groups) are already exploiting it in the wild as part of an ongoing extortion and data theft campaign._\\n\\n## The Vulnerability\\n\\nResearchers recently published a detailed analysis and PoC showing CVE\u20112025\u201161882 is not a single bug but rather a multi\u2011stage exploit chain. The attacker begins with an unauthenticated HTTP POST to OA_HTML\/configurator\/UiServlet that supplies XML containing a controllable return_url. That URL is used to trigger an outbound HTTP request (classic SSRF). From there the chain uses CRLF\/header injection and HTTP connection reuse to frame additional requests, pivots to a local HTTP service (not properly constrained), and finally delivers a malicious XSL stylesheet that the server processes, leading to arbitrary code execution.\\n\\nSome of the techniques observed or hypothesized in the chain include:\\n\\n  * **SSRF\/misrouting:** attackers cause Oracle EBS to fetch attacker-controlled XSLT payloads via crafted return_url parameters.\\n  * **CRLF injection:** to inject or smuggle headers or requests in the HTTP pipeline.\\n  * **XSLT-based payload execution:** The attacker\u2019s hosted XSL template contains embedded Java code (Base64-encoded) that triggers Java\u2019s Script Engine (e.g., Runtime.exec(\u2026)) via eval-like flows within the XSLT environment.\\n  * **Reverse shell\/outbound connections:** Observed commands include attempts to spawn bash shells connecting back to attacker infrastructure.\\n  * **Multi-stage chaining:** The exploit is not just one flaw, but rather a chain of smaller weaknesses combined to produce a full pre-auth RCE.\\n\\n\\n\\nIn practical terms, the attacker often begins by issuing a crafted HTTP request to endpoints such as \/OA_HTML\/SyncServlet, triggering the authentication bypass, then moving through RF.jsp, OA.jsp, or UiServlet paths to deliver the malicious XSLT.\\n\\nBecause the payload is executed in the context of the EBS Java application, the attacker can achieve full system-level command execution, drop web shells, pivot laterally, and exfiltrate data.\\n\\nOracle\u2019s advisory and the analysis indicate EBS versions 12.2.3 through 12.2.14 are in scope, meaning a large class of EBS deployments are vulnerable until patched. Because EBS often underpins finance, HR, and core ERP functions, risk and potential impact are high.\\n\\n## What We\u2019ve Seen\\n\\nIn just one day, we\u2019ve already seen more than 557,000 attack attempts exploiting this vulnerability. These attacks are global, targeting more than 25 countries, although they\u2019re primarily hitting the US, UK, and France.\\n\\nGaming, computing, financial, and business sites are the most hard-hit by attack attempts.\\n\\nCl0p is already alleged to have exploited the vulnerability since August, and it\u2019s also potentially been used by LAPSUS$, Scattered Spider, and ShinyHunters.\\n\\n## Bottom line\\n\\nCVE\u20112025\u201161882 is a compact, high\u2011impact pre\u2011auth RCE chain that weaponizes SSRF and XSLT processing.\\n\\nImperva Threat Research Group tracked and identified the exploitation chain of this vulnerability ensuring that Imperva customers with Cloud WAF or On-Prem WAF are now protected out of the box against it\\n\\nThe post CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE appeared first on Blog.&#8221;,&#8221;published&#8221;:&#8221;2025-10-13T22:29:59&#8243;,&#8221;modified&#8221;:&#8221;2025-10-13T22:29:59&#8243;,&#8221;type&#8221;:&#8221;impervablog&#8221;,&#8221;title&#8221;:&#8221;CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-61882&#8243;],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:9.8,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.imperva.com\/blog\/cve-2025-61882-imperva-customers-protected-against-critical-oracle-ebs-zero-day-rce\/&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;AI processing failed &#8211; returned non-JSON response&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-14T02:05:08&#8243;,&#8221;description&#8221;:&#8221;_TL;DR: In early October 2025, Oracle released an emergency security alert addressing CVE-2025-61882, a high-severity unauthenticated remote code execution (RCE) vulnerability in the Concurrent Processing&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[9,6,8,35,12,59,13,7,11,5],"class_list":["post-21361","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-critical","tag-cve","tag-cvss","tag-cvss-98","tag-exploit","tag-impervablog","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=21361\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-10-14T02:05:08&#8243;,&#8221;description&#8221;:&#8221;_TL;DR: In early October 2025, Oracle released an emergency security alert addressing CVE-2025-61882, a high-severity unauthenticated remote code execution (RCE) vulnerability in the Concurrent Processing...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=21361\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-13T21:45:24+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21361#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21361\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2\",\"datePublished\":\"2025-10-13T21:45:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21361\"},\"wordCount\":707,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.8\",\"exploit\",\"impervablog\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=21361#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21361\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21361\",\"name\":\"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-10-13T21:45:24+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21361#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=21361\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21361#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=21361","og_locale":"en_US","og_type":"article","og_title":"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-10-14T02:05:08&#8243;,&#8221;description&#8221;:&#8221;_TL;DR: In early October 2025, Oracle released an emergency security alert addressing CVE-2025-61882, a high-severity unauthenticated remote code execution (RCE) vulnerability in the Concurrent Processing...","og_url":"https:\/\/zero.redgem.net\/?p=21361","og_site_name":"zero redgem","article_published_time":"2025-10-13T21:45:24+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=21361#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=21361"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2","datePublished":"2025-10-13T21:45:24+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=21361"},"wordCount":707,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.8","exploit","impervablog","news","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=21361#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=21361","url":"https:\/\/zero.redgem.net\/?p=21361","name":"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-10-13T21:45:24+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=21361#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=21361"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=21361#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"CVE-2025-61882: Imperva Customers Protected Against Critical Oracle EBS Zero-Day RCE_IMPERVABLOG:F67CE10F1C282EBF524B9D36E6BBB3E2"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/21361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=21361"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/21361\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=21361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=21361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=21361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}