元のタイトル: Oracle Issues Emergency Patch for E-Business Suite Zero-Day CVE-2025-61882
最初の項目は常にピンの出典です。全体の確度は、各資料が上記の開始・終了時刻をどれだけ強く裏付けているかの加重平均です。最新の資料より180日古くなるごとに、重みは半分になります。
オラクルのセキュリティアラート・アドバイザリーCVE-2025-61882の変更履歴には「2025年10月4日 Rev 1. 初版」とある。
Oracle's[1] second E-Business Suite alert, for a 7.5-rated Configurator Runtime UI flaw, released 11 October 2025.
CrowdStrike puts the first known exploitation at 9 August 2025; watchTowr found the leaked exploit is a chain needing a single HTTP request.[1]
CISA added CVE-2025-61882 Oracle[1][2] E-Business Suite to its Known Exploited Vulnerabilities catalog on 6 October 2025.
Reports the alert and Mandiant CTO Charles Carmakal's statement that Clop exploited CVE-2025-61882 and July-patched flaws to steal data in August 2025.[1]
足りない点や誤りがありますか? このピンを裏付けるリンク、別の開始日・終了日とその理由、欠けている情報や誤っている情報を、自由に書いてください。AIがこのピンの出典と照らし合わせ、より良い情報源を探し、裏付けとなるページがあれば参考資料として追加します。ピン自身の出典が引き続き最も重視されます。