⚠ Actively exploited
Added to CISA KEV on 2025-11-21. Federal agencies required to patch by 2025-12-12. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2025-61757

Severity
9.8CRITICAL
EPSS
88.1%
top 0.52%
CISA KEV
KEV
Added 2025-11-21
Due 2025-12-12
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 21
KEV addedNov 21
Latest updateDec 2
KEV dueDec 12
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDoracle/identity_manager12.2.1.4.0, 14.1.2.1.0+1
CVEListV5oracle_corporation/identity_manager12.2.1.4.0, 14.1.2.1.0+1

🔴Vulnerability Details

3
CVEList
CVE-2025-61757: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices)2025-10-21
GHSA
GHSA-v5gw-cq42-m6w2: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices)2025-10-21
VulnCheck
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability2025

💥Exploits & PoCs

1
Nuclei
Oracle Identity Manager REST WebServices - Authentication Bypass

🔍Detection Rules

2
Suricata
ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M1 (CVE-2025-61757)2025-12-02
Suricata
ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M2 (CVE-2025-61757)2025-12-02

📋Vendor Advisories

2
CISA
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability2025-11-21
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: REST WebServices — CVE-2025-617572025-10-15

🕵️Threat Intelligence

1
Bleepingcomputer
CISA warns Oracle Identity Manager RCE flaw is being actively exploited2025-11-21
CVE-2025-61757 (CRITICAL CVSS 9.8) | Vulnerability in the Identity Manag | cvebase.io