ID:12225 - Exploit for Input validation error in Oracle E-Business Suite and Oracle Concurrent Processing - CVE-2025-61882
Published: January 4, 2026
Oracle E-Business Suite
Oracle Concurrent Processing
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the BI Publisher Integration component. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.