CVE-2025-61757
published 2025-10-21CVE-2025-61757: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2025-12-12
Exploited in the wild
EPSS
88.31%
99.8th percentile
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | identity_manager | — | — |
| oracle | identity_manager | — | — |
| oracle_corporation | identity_manager | — | — |
| oracle_corporation | identity_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
sigma↗
POST /iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl HTTP/1.1
- →Detect HTTP POST requests to the ;.wadl-suffixed groovyscriptstatus endpoint — the auth bypass is triggered by appending ';.wadl' to the URL path, bypassing authentication on the REST WebServices component. ↗
- →A successful exploit response contains the string 'Script Compilation Successful' with content-type 'text/plain' and HTTP 200 status — use this as a confirmation indicator in detection rules. ↗
- →Unauthenticated access to the groovyscriptstatus endpoint (HTTP 401 without ;.wadl suffix, HTTP 200 with ;.wadl suffix) indicates active exploitation attempts — monitor for this status code differential. ↗
- →Scanning activity was observed using an anomalously old user agent (Chrome 60 on Windows 10) across multiple source IPs — flag this UA string in web server logs as a strong indicator of CVE-2025-61757 reconnaissance. ↗
- →Exploitation abuses Groovy annotation-processing features at compile time — monitor for unexpected process spawning or outbound connections from the Oracle Identity Manager JVM process following requests to the groovyscriptstatus endpoint. ↗
- →Shodan/FOFA exposure query for affected instances: search for title 'oracle access management' to identify internet-exposed Oracle Identity Manager deployments. ↗
- →Zero-day exploitation was observed as early as August 30, weeks before the October 2025 patch — review web server logs from August 30 through September 9 for POST requests to the ;.wadl-suffixed endpoints. ↗
- ·The ;.wadl suffix auth bypass technique also applies to the templates endpoint — ensure detection rules cover both vulnerable paths, not just groovyscriptstatus. ↗
- ·The Nuclei template uses a two-step flow: step 1 confirms the endpoint returns HTTP 401 with an Oracle header (verifying target identity), step 2 sends the exploit POST — single-step detections may miss context. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
cisa·2025-11-21·CVSS 9.8
CVE-2025-61757 [CRITICAL] CWE-306 Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Vulnerability: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Affected: Oracle Fusion Middleware
Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://www.oracle.com/security-alerts/cpuoct2025.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61757
Remediation Due Date: 2025-12-12
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: REST WebServices — CVE-2025-61757
vendor_oracle·2025-10-15·CVSS 9.8
CVE-2025-61757 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: REST WebServices — CVE-2025-61757
Oracle Oracle Fusion Middleware Risk Matrix: REST WebServices vulnerability
CVE: CVE-2025-61757
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
GHSA
GHSA-v5gw-cq42-m6w2: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices)
ghsa_unreviewed·2025-10-21
CVE-2025-61757 [CRITICAL] CWE-306 GHSA-v5gw-cq42-m6w2: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices)
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
vulncheck·2025·CVSS 9.8
CVE-2025-61757 [CRITICAL] CWE-306 Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
Affected: Oracle Fusion Middleware
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://isc.sans.edu/diary/rss/32506; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.imperva.com/blog/cve-2025-61757-imperva-customers-protected-against-critical-oracle-identity-manager-authentication-bypass-leading-to-remote-code-execution/; https:/
Suricata
ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M1 (CVE-2025-61757)
suricata·2025-12-02·CVSS 9.8
CVE-2025-61757 [CRITICAL] ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M1 (CVE-2025-61757)
ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M1 (CVE-2025-61757)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M1 (CVE-2025-61757)"; flow:established,to_server; http.uri; content:"/iam/governance/"; startswith; fast_pattern; content:"?"; distance:0; content:"wsdl"; nocase; distance:0; reference:url,slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/; reference:cve,2025-61757; classtype:attempted-admin; sid:2065975; rev:1; metadata:affected_product Oracle_Identity_Manager, attack_target Server, tls_state TLSDecrypt, created_at 2025_12_02, cve CVE_2025_61757, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, tag Description_Generated
Suricata
ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M2 (CVE-2025-61757)
suricata·2025-12-02·CVSS 9.8
CVE-2025-61757 [CRITICAL] ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M2 (CVE-2025-61757)
ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M2 (CVE-2025-61757)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Oracle Identity Governance Pre-Auth ByPass M2 (CVE-2025-61757)"; flow:established,to_server; http.uri; content:"/iam/governance/"; startswith; fast_pattern; content:"|3b|"; distance:0; content:"|2e|wadl"; distance:0; reference:url,slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/; reference:cve,2025-61757; classtype:attempted-admin; sid:2065976; rev:1; metadata:affected_product Oracle_Identity_Manager, attack_target Server, tls_state TLSDecrypt, created_at 2025_12_02, cve CVE_2025_61757, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_
Nuclei
Oracle Identity Manager REST WebServices - Authentication Bypass
nuclei·CVSS 9.8
CVE-2025-61757 [CRITICAL] Oracle Identity Manager REST WebServices - Authentication Bypass
Oracle Identity Manager REST WebServices - Authentication Bypass
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager.
Template:
id: CVE-2025-61757
info:
name: Oracle Identity Manager REST WebServices - Authentication Bypass
author: ritikchaddha
severity: critical
description: |
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploi
Hackernews
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
blogs_hackernews·2026-03-21·CVSS 9.8
CVE-2026-21992 [CRITICAL] Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution.
The vulnerability, tracked as CVE-2026-21992 , carries a CVSS score of 9.8 out of a maximum of 10.0.
"This vulnerability is remotely exploitable without authentication," Oracle said in an advisory. "If successfully exploited, this vulnerability may result in remote code execution."
CVE-2026-21992 affects the following versions -
Oracle Identity Manager ver
Tenable
CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability
blogs_tenable·2026-03-20·CVSS 9.8
[CRITICAL] CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
CISA warns Oracle Identity Manager RCE flaw is being actively exploited
blogs_bleepingcomputer·2025-11-21·CVSS 9.8
CVE-2025-61757 [CRITICAL] CISA warns Oracle Identity Manager RCE flaw is being actively exploited
## CISA warns Oracle Identity Manager RCE flaw is being actively exploited
## Lawrence Abrams
The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning government agencies to patch an Oracle Identity Manager tracked as CVE-2025-61757 that has been exploited in attacks, potentially as a zero-day.
CVE-2025-61757 is a pre-authentication RCE vulnerability in Oracle Identity Manager, discovered and disclosed by Searchlight Cyber analysts Adam Kues and Shubham Shahflaw.
?WSDL
;.wadl
Once unauthenticated access is gained, attackers can reach a Groovy script, which is a compilation endpoint that does not typically execute a script. However, it can be abused to run malicious code at compile time through Groovy's annotation-processing features.
This chain of flaws enabled the
Qualys
Oracle Critical Patch Update, October 2025 Security Update Review
blogs_qualys·2025-10-23
Oracle Critical Patch Update, October 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 374 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 73, constituting about 19% of the total patches released. Oracle Communications Applications and Oracle Financial Services Applications followed, with 64 and 33 security patches.
298 of the 374 security patches provided by the October Critical Patch Update (
Qualys
Oracle Critical Patch Update, October 2025 Security Update Review | Qualys
blogs_qualys·2025-10-23
Oracle Critical Patch Update, October 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 374 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 73, constituting about 19% of the total patches released. Oracle Communications Applications and Oracle Financial Services Applications followed, with 64 and 33 security patches.
298 of the 374 security patches provided by the October Critical Patch Upd
Recorded Future
November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from October
blogs_recorded_future·CVSS 5.4
CVE-2025-64446 [MEDIUM] November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from October
# November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from October
November 2025 saw a significant 69% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 10 vulnerabilities requiring immediate attention, down from 32 in October.
What security teams need to know:
- Fortinet leads concerns: Two critical FortiWeb vulnerabilities (CVE-2025-64446 and CVE-2025-58034) are under active exploitation
- LANDFALL spyware campaign: Threat actors weaponized Samsung's image processing flaw (CVE-2025-21042) for zero-click Android attacks
- Public exploits proliferate: Seven of ten vulnerabilities have public proof-of-concept code available
- OS Command Injection and Out-of-bounds Write were tied as the most common weakness types
Bottom line: Th
Wiz
CVE-2026-21992 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-21992 [CRITICAL] CVE-2026-21992 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21992 :
Oracle Identity Manager vulnerability analysis and mitigation
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager and Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager and Oracle Web Services Manager. Note: Oracle Web Services Manager is installed with an Oracle Fusion Middleware Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integr
Greynoiseio
NoiseLetter November 2025
blogs_greynoiseio
NoiseLetter November 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2025-10-21
Published
2025-11-21
Added to CISA KEV
Exploited in the wild