Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Oracle E-Business Suite
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .9779 99.9 YES
AFFECTED
Product Versions Fixed
Oracle Configurator 12.2.3 – —
TIMELINE
Oct 3 Reserved by oracle
Oct 20 Added to CISA KEV, remediation due 2025-11-10
Oct 20 Published (CNA: oracle)
Aug 3 EXPLOIT PUBLISHED — CVE-2025-61884 (Oracle Corporation Oracle Configurator). Public exploit reference added.
Description
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| October 3, 2025 | Reserved | Reserved by oracle |
| October 20, 2025 | KEV ADDED | Added to CISA KEV, remediation due 2025-11-10 |
| October 20, 2025 | Published | Published (CNA: oracle) |
| August 3, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2025-61884 (Oracle Corporation Oracle Configurator). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Oracle Corporation | Oracle Configurator | — | 12.2.3 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-61884 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.