E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as “enterprise” to any required insurance, even then.
Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday.
It’s pretty common in a killchain following a server side request forgery since the traffic isn’t seem by the WAF.
Example: https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882
It really is not common in the common era.
E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as “enterprise” to any required insurance, even then.
Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday.