Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
2 months ago

Investigating: Cl0p Reportedly Breached Oracle E-Business Suite (EBS) Systems

Tenable's Research Special Operations (RSO) team is investigating reports of breaches connected to Oracle E-Business Suite (EBS) systems by the Cl0p extortion group. 

As of October 3, there have been no specific vulnerabilities (or CVEs) identified in connection with the attacks. However, Rob Duhart, Chief Security Officer at Oracle, published the following in a blog post:

Oracle is aware that some Oracle E-Business Suite (EBS) customers have received extortion emails. Our ongoing investigation has found the potential use of previously identified vulnerabilities that are addressed in the July 2025 Critical Patch Update.  Oracle reaffirms its strong recommendation that customers apply the latest Critical Patch Updates.

In the July 2025 Critical Patch Update (CPU), there were 165 unique CVEs patched, including nine associated with Oracle EBS:

CVEProductCVSSv3
CVE-2025-30743Oracle Lease and Finance Management8.1
CVE-2025-30744Oracle Mobile Field Service8.1
CVE-2025-50105Oracle Universal Work Queue8.1
CVE-2025-50071Oracle Applications Framework6.4
CVE-2025-30746Oracle iStore6.1
CVE-2025-30745Oracle MES for Process Manufacturing6.1
CVE-2025-50107Oracle Universal Work Queue6.1
CVE-2025-30739Oracle CRM Technical Foundation5.5
CVE-2025-50090Oracle Applications Framework5.4

Cl0p has historically been linked to the exploitation of zero-day vulnerabilities including in managed file transfer platforms, such as Cleo, MOVEit, GoAnywhere and Accellion.

If and when more definitive information becomes available, we will update this post and or publish more details on the Tenable Blog.

No RepliesBe the first to reply