ZeroHour

CVE-2025-61757

KEVlarge

Unauthenticated Takeover of Oracle Identity Manager via REST WebServices

CISA: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

CVSS 3.1
9.8 critical
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2025-61757 is a critical missing-authentication flaw (CWE-306) in the REST WebServices component of Oracle Identity Manager, part of Oracle Fusion Middleware, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated attacker with network access can send HTTP requests to the REST endpoints without any credentials or user interaction. Successful exploitation results in takeover of Identity Manager, with high-impact confidentiality, integrity, and availability consequences (CVSS 3.1 base score 9.8). Any organization running the affected versions of Oracle Identity Manager — typically large enterprises and public-sector organizations using it for identity and access management — is exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-21, news reports describe it as an actively exploited zero-day, and EPSS assigns an 88.3% probability of exploitation within 30 days.

What to do: Immediately apply Oracle's fix for CVE-2025-61757 to Identity Manager 12.2.1.4.0 and 14.1.2.1.0 per Oracle's security advisory (federal agencies must follow BOD 22-01 timelines). Until patching is complete, restrict untrusted and internet-facing HTTP access to the Identity Manager REST WebServices endpoints, and review logs for signs of compromise given confirmed in-the-wild exploitation. Also verify that the separate unauthenticated RCE in Identity Manager (CVE-2026-21992), which Oracle has patched, is remediated in the same maintenance cycle.

Affected
Oracle Identity Manager (REST WebServices component, Oracle Fusion Middleware)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
largeon the order of tens of thousands of enterprise deployments worldwide; the share with the REST endpoint exposed over HTTP is unknown — No public install counts or internet-exposure scan data exist for this product, so the estimate is based on deployment patterns: Oracle Identity Manager is a broadly deployed enterprise IAM component of Oracle Fusion Middleware commonly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle Fusion Middleware
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
identity manager
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news