PT-2025-42978 · Oracle · Oracle Fusion Middleware Identity Manager
Published
2025-10-21
·
Updated
2025-11-30
·
CVE-2025-61757
CVSS v2.0
10
10
Critical
| Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Identity Manager versions 12.2.1.4.0 through 14.1.2.1.0
Description
This is a critical vulnerability in Oracle Identity Manager’s REST WebServices component that allows unauthenticated attackers to remotely execute code via HTTP. The vulnerability stems from missing authentication for a critical function, enabling attackers to bypass security checks and execute arbitrary code. Exploitation has been observed in the wild since August 2025, and CISA has added this vulnerability (CVE-2025-61757) to its Known Exploited Vulnerabilities catalog. Attackers can exploit this by appending strings like '?WSDL' or ';.wadl' to URLs, gaining access to internal APIs, including the Groovy script status API, which compiles and executes submitted scripts. Successful exploitation can lead to a complete system takeover.
Recommendations
Apply the latest security patch released by Oracle for Oracle Identity Manager versions 12.2.1.4.0 through 14.1.2.1.0.
Restrict external access to the affected component using network segmentation or access control lists (ACLs).
Monitor logs for unusual activity, specifically requests targeting the vulnerable API endpoints with payloads around 556 bytes.
Consider temporarily disabling the Groovy script status API if it is not essential for operations.
Fix
RCE
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-14708
CVE-2025-61757
Affected Products
Oracle Fusion Middleware Identity Manager
References · 135
- https://bdu.fstec.ru/vul/2025-14708 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-61757 · Security Note
- https://oracle.com/security-alerts/cpuoct2025.html · Security Note, Vendor Advisory
- https://twitter.com/sans_isc/status/1991551169949495785 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1993056028384976998 · Twitter Post
- https://twitter.com/RedLegg/status/1993066690511356135 · Twitter Post
- https://reddit.com/r/pwnhub/comments/1p3u8bx/cisa_alerts_critical_oracle_identity_manager · Reddit Post
- https://twitter.com/GobySec/status/1993225173454274866 · Twitter Post
- https://twitter.com/_UncleHacker_/status/1992209579355025582 · Twitter Post
- https://twitter.com/STRATINT_AI/status/1992141340163940733 · Twitter Post
- https://t.me/aptreports/23921 · Telegram Post
- https://twitter.com/infosec_au/status/1991343649427431883 · Twitter Post
- https://twitter.com/PurpleOps_io/status/1992488671384101362 · Twitter Post
- https://reddit.com/r/pwnhub/comments/1p5ys6o/critical_flaw_in_oracle_identity_manager_under · Reddit Post
- https://twitter.com/CISACyber/status/1991974702139482420 · Twitter Post