Article Details

Scrape Timestamp (UTC): 2025-10-07 05:20:47.034

Source: https://thehackernews.com/2025/10/oracle-ebs-under-fire-as-cl0p-exploits.html

Original Article Text

Click to Toggle View

Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks. CrowdStrike on Monday said it's attributing the exploitation of a recently disclosed security flaw in Oracle E-Business Suite with moderate confidence to a threat actor it tracks as Graceful Spider (aka Cl0p), and that the first known exploitation occurred on August 9, 2025. The exploitation involves the exploitation of CVE-2025-61882 (CVSS score: 9.8), a critical vulnerability that facilitates remote code execution without authentication. The cybersecurity company also noted that it's currently not known how a Telegram channel "insinuating" collaboration between Scattered Spider, LAPSUS$ (aka Slippy Spider), and ShinyHunters came into the possession of an exploit for the flaw, and if they and other threat actors have leveraged it in real-world attacks. The Telegram channel has been observed sharing the purported Oracle EBS exploit, while criticizing Graceful Spider's tactics. The observed activity so far involves an HTTP request to /OA_HTML/SyncServlet, resulting in an authentication bypass. The attacker then targets Oracle's XML Publisher Template Manager by issuing GET and POST requests to /OA_HTML/RF.jsp and /OA_HTML/OA.jsp to upload and execute a malicious XSLT template, The commands in the malicious template are executed when it is previewed, resulting in an outbound connection from the Java web server process to attacker-controlled infrastructure over port 443. The connection is subsequently used to remotely load web shells to execute commands and establish persistence. It's believed that one or more threat actors are in possession of the CVE-2025-61882 exploit for purposes of data exfiltration. "The proof-of-concept disclosure and the CVE-2025-61882 patch release will almost certainly encourage threat actors – particularly those familiar with Oracle EBS — to create weaponized POCs and attempt to leverage them against internet-exposed EBS applications," it said. In a separate analysis, WatchTowr Labs said, "The chain demonstrates a high level of skill and effort, with at least five distinct bugs orchestrated together to achieve pre-authenticated remote code execution." The entire sequence of events is as follows - The attack, at its core, takes advantage of the fact that the JSP file can load an untrusted stylesheet from a remote URL, opening the door for an attacker to achieve arbitrary code execution. "This combination lets an attacker control request framing via the SSRF and then reuse the same TCP connection to chain additional requests, increasing reliability and reducing noise," the company said. "HTTP persistent connections, also known as HTTP keep-alive or connection reuse, let a single TCP connection carry multiple HTTP request/response pairs instead of opening a new connection for every exchange." CVE-2025-61882 has since been added to the Known Exploited Vulnerabilities (KEV) catalog by the Cybersecurity and Infrastructure Security Agency (CISA), noting that it has been used in ransomware campaigns, urging federal agencies to apply the fixes by October 27, 2025. "Cl0p has been exploiting multiple vulnerabilities in Oracle EBS since at least August 2025, stealing large amounts of data from several victims, and has been sending extortion emails to some of those victims since last Monday," Jake Knott, principal security researcher at watchTowr, said in a statement. "Based on the evidence, we believe this is Cl0p activity, and we fully expect to see mass, indiscriminate exploitation from multiple groups within days. If you run Oracle EBS, this is your red alert. Patch immediately, hunt aggressively, and tighten your controls — fast."

Daily Brief Summary

VULNERABILITIES // Cl0p Exploits Critical Oracle EBS Flaw for Data Exfiltration

CrowdStrike attributes the exploitation of Oracle E-Business Suite's CVE-2025-61882 to the threat actor Graceful Spider, known as Cl0p, with moderate confidence.

The vulnerability, scoring 9.8 on the CVSS scale, allows remote code execution without authentication, posing significant risks to affected systems.

An observed attack sequence involves exploiting Oracle's XML Publisher Template Manager to upload and execute malicious templates, leading to persistent access.

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-61882 to its Known Exploited Vulnerabilities catalog, urging immediate patching by October 27, 2025.

Cl0p has been actively exploiting this flaw since August 2025, leading to data theft and extortion attempts against multiple Oracle EBS users.

A Telegram channel has shared the exploit while criticizing Graceful Spider, indicating potential collaboration or competition among threat actors.

Security experts recommend urgent patching, aggressive threat hunting, and enhanced security controls to mitigate risks associated with this vulnerability.