Junglewise Threat Intelligence

CVE-2025-61757: Oracle Identity Manager missing authentication in REST WebServices

CVE-2025-61757 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-11-21

Technologies: Oracle Fusion Middleware. Vendors: Oracle.

Executive brief

Oracle Identity Manager, a tool used to manage user identities and access rights across an organization, contains a critical security flaw. An unauthorized person can remotely bypass security checks to take full control of the system. This could lead to the theft of sensitive user data, unauthorized access to other corporate systems, or a complete shutdown of identity services.

Technical details

A missing authentication for critical function vulnerability (CWE-306) exists in the REST WebServices component of Oracle Identity Manager. The flaw allows a remote, unauthenticated attacker to send specially crafted HTTP requests to the affected service. Because the component fails to properly verify the identity of the requester before performing sensitive operations, an attacker can achieve a complete takeover of the Identity Manager instance. This vulnerability is reportedly being exploited in the wild. Oracle has addressed this issue in the October 2025 Critical Patch Update.

Affected products

  • Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2025-10-21: disclosed: Initial CVE publication by Oracle
  • 2025-10-21: patched: Addressed in Oracle October 2025 Critical Patch Update
  • 2025-11-21: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-11-21: exploited: Confirmed active exploitation in the wild

Related threats