ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

CISA Urges Patch of Actively Exploited Flaw in Oracle Identity Manager

criticalVulnerability exploited in the wildimportance 60CVE-2025-61757CVE-2021-35587

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35587
Unauthenticated RCE in Oracle Access Manager (OpenSSO Agent)

CVE-2021-35587 is a critical (CVSS 9.8) missing-authentication flaw (CWE-306) in the OpenSSO Agent component of Oracle Access Manager, part of Oracle Fusion Middleware. An unauthenticated attacker with network access can send crafted HTTP requests to the affected component and, because the endpoint requires no authentication, achieve takeover of Oracle Access Manager — effectively pre-authentication remote code execution with high impact on confidentiality, integrity, and availability. Organizations running Oracle Access Manager 11.1.2.3.0, 12.2.1.3.0, or 12.2.1.4.0 are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-11-28, and security press reported more than 150 internet-exposed Oracle Access Management systems. EPSS assigns a 96.3% probability of exploitation within 30 days, although no public proof-of-concept code is known.

Do: Apply Oracle's update for CVE-2021-35587 per vendor instructions (delivered via the Oracle Critical Patch Update covering this flaw) to bring Access Manager 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0 to a fixed release; this is the required action in CISA's KEV entry. Until patched, restrict HTTP access to OpenSSO Agent/Access Manager endpoints at the perimeter and review access logs for signs of unauthenticated exploitation.

9.896% KEV
  • Oracle Access Manager (component: OpenSSO Agent) of Oracle Fusion Middleware 11.1.2.3.0, 12.2.1.3.0, 12.2.1.4.0
niche≈150+ internet-exposed Oracle Access Manager systems identified by public scans
CVE-2025-61757
Unauthenticated Takeover of Oracle Identity Manager via REST WebServices

CVE-2025-61757 is a critical missing-authentication flaw (CWE-306) in the REST WebServices component of Oracle Identity Manager, part of Oracle Fusion Middleware, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated attacker with network access can send HTTP requests to the REST endpoints without any credentials or user interaction. Successful exploitation results in takeover of Identity Manager, with high-impact confidentiality, integrity, and availability consequences (CVSS 3.1 base score 9.8). Any organization running the affected versions of Oracle Identity Manager — typically large enterprises and public-sector organizations using it for identity and access management — is exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-21, news reports describe it as an actively exploited zero-day, and EPSS assigns an 88.3% probability of exploitation within 30 days.

Do: Immediately apply Oracle's fix for CVE-2025-61757 to Identity Manager 12.2.1.4.0 and 14.1.2.1.0 per Oracle's security advisory (federal agencies must follow BOD 22-01 timelines). Until patching is complete, restrict untrusted and internet-facing HTTP access to the Identity Manager REST WebServices endpoints, and review logs for signs of compromise given confirmed in-the-wild exploitation. Also verify that the separate unauthenticated RCE in Identity Manager (CVE-2026-21992), which Oracle has patched, is remediated in the same maintenance cycle.

9.888% KEV
  • Oracle Identity Manager (REST WebServices component, Oracle Fusion Middleware) 12.2.1.4.0, 14.1.2.1.0
largeon the order of tens of thousands of enterprise deployments worldwide; the share with the REST endpoint exposed over HTTP is unknown
Full article261 words · extracted from infosecurity-magazine.com · click to collapse

A critical security vulnerability in Oracle Identity Manager is being exploited in the wild, according to the US Cybersecurity and Infrastructure Security Agency (CISA).

The flaw, tracked as CVE-2025-61757, was revealed by Searchlight Cyber on November 20.

It was reported by Oracle on November 21 and added to CISA Known Exploited Vulnerabilities (KEV) catalog the same day following reports of active exploitation.

The vulnerability lies in the REST WebServices component of the Identity Manager, part of Oracle Fusion Middleware.

It allows unauthenticated remote attackers with network access via HTTP to execute arbitrary code on affected systems (versions 12.2.1.4.0 and 14.1.2.1.0) and can result in the takeover of Oracle Identity Manager.

It has been allocated a severity score (CVSS) of 9.8, meaning the vulnerability is critical.

This vulnerability poses a severe risk because no prior credentials or system access are needed to exploit it.

The easy authentication bypass paired with a consistent remote code execution (RCE) method makes it a prime target for ransomware operators and advanced persistent threat (APT) groups, including state-backed actors.

CISA urged organizations running Oracle Identity Governance Suite 12c to apply the relevant patches immediately or isolate the affected services from the public internet.

The Searchlight Cyber researchers discovered the bug while investigating a breach that occurred earlier in 2025 affecting Oracle Cloud’s login service (login.us2.oraclecloud.com).

During the incident, a threat actor was observed exploiting an older vulnerability impacting Oracle products, CVE-2021-35587.

The breach led to the compromise of six million records and over 140,000 Oracle Cloud tenants.

Photo credits: gguy / Tada Images / Shutterstock

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-kev-oracle-identity-manager/