CSA Singapore warned of full compromise risk. Oracle has not officially confirmed active exploitation in advisories. Restrict public EBS web access.