CVE-2025-61757Disclosure(oracle / identity_manager)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch oracle identity_manager systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-18); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
identity_manager

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-21: 1Mentions · 2026-03-23: 1Mentions · 2026-09-24: 1Active Exploitation · 2026-03-21: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 1Technical Details · 2026-09-24: 103-1803-2103-2309-24
Signal classification4 categories
Disclosure
240.0%
General
120.0%
Active Exploitation
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1General1
2026-03-211
Active Exploitation1
2026-03-231
Patch1
2026-09-241
Disclosure1
Full discourse5 posts
  • reverseame@reverseame
    Disclosure

    Breaking Oracle’s Identity Manager: Pre-Auth RCE (CVE-2025-61757) https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/

    Post summary

    The text announces a newly discovered Oracle Identity Manager pre‑authentication remote code execution vulnerability (CVE‑2025‑61757) and links to a research article presumably detailing the issue.

    03094910
    21.8K followersView on X
  • CVE Brief@DailyCVEBrief
    Disclosure

    Full Look Back writeup: the Thor and Oblix lineage, the allowlist filter behind CVE-2025-61757, and what is still unknown about the fix: https://cvebrief.com/cve/cve-2026-21992/ https://t.co/QmbKgzhVWG

    Post summary

    The tweet announces a detailed technical writeup analyzing the lineage and allowlist filter mechanism of CVE-2025-61757, highlighting unresolved questions about the vendor's fix.

    0000046
    33 followersView on X
  • CybrPulse@CybrPulse
    Patch

    Oracle issued an emergency out-of-band patch for CVE-2026-21992 — unauthenticated RCE via HTTP in Identity Manager and Web Services Manager (CVSS 9.8). Affects 12.2.1.4.0 and 14.1.2.1.0. Mirrors CVE-2025-61757, which was actively exploited. Apply immediately.

    Post summary

    Oracle issued an emergency patch for the RCE CVE-2026-21992 and urges immediate application, noting the vulnerability mirrors a previously exploited CVE-2025-61757.

    0000082
    21 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2025-61757 to achieve unauthenticated RCE in Oracle Identity Manager, then escalating privileges for lateral movement across networks. Runtime segmentation helps contain such post-compromise activity in identity infrastructure. #IdentitySecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/oracle-identity-manager-2025-cve-2025-61757-unauthenticated-rce

    Post summary

    The text indicates that attackers are actively exploiting CVE-2025-61757 to achieve unauthenticated RCE in Oracle Identity Manager and subsequently elevate privileges for lateral movement, highlighting the real‑world threat and the need for containment measures.

    00000102
    1.9K followersView on X
  • Ercan Şahin 🍉@ErcanSah1n
    General

    CVE-2025-61757 - Oracle Fusion Middleware vulnerability https://dy.si/jr2kV https://t.co/pfE8JxcOHP

    Post summary

    The tweet simply references CVE-2025-61757 with a brief link, offering no details on PoC, exploitation, patching, or technical specifics.

    0000074
    126 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleidentity_manager12.2.1.4.0--
Apporacleidentity_manager14.1.2.1.0--

Explore more