Skip to content

Oracle E-Business Suite β€” Security Intelligence & Vulnerability Profile


ParameterTechnical Specification
Official NameOracle E-Business Suite
Vendor / Projectoracle
Canonical IDoracle:ebusiness_suite
Versioning Schemegeneric
CPE Identifierscpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:concurrent_processing:*:*:*:*:*:*:*:*
Overall PostureCRITICAL
Recommended Safe Release12.2.14-CPU-OCT-2025

Documented CVEs

2 vulnerabilities cataloged in the Hermes intelligence repository.

CISA KEV Entries

1 flaws with confirmed active in-the-wild exploitation.

Weaponized Exploits

1 vulnerabilities with publicly available PoCs or weaponized exploit tooling.

Remediation Target

Recommended upgrade to 12.2.14-CPU-OCT-2025 to neutralize known flaws.


Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:

Current HTS Score

0 / 100

= Stable over 30d

Max EPSS (Exploitation)

99.7 %

= Stable over 30d

CISA KEV Activity

1

Active in-the-wild exploitation

HTS Trend Curve (D-30 β†’ Today)2026-08-12 β†’ 2026-09-10

3. Vulnerability History & Version Applicability Matrix

Section titled β€œ3. Vulnerability History & Version Applicability Matrix”
CVECVSS ScoreEPSS ProbabilityCISA KEVAffected VersionsFixed InHermes Analysis
CVE-2025-618829.8 (CRITICAL)99.7%CISA KEVv12.2.3 to v12.2.1412.2.14-CPU-OCT-2025Analysis β†’
CVE-2025-501058.1 (HIGH)0.4%Nov12.2.3 to v12.2.1412.2.14-CPU-JUL-2025Analysis β†’

Vulnerabilities impacting Oracle E-Business Suite are actively leveraged in real-world intrusion campaigns:


Are you operating Oracle E-Business Suite in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: