Vulnerability record · CVE-2025-61757 · published 21 October 2025
CVE-2025-61757: Oracle Identity Manager REST WebServices missing authentication allows takeover
Oracle · Identity Manager
Oracle Fusion Middleware Identity Manager exposes a REST WebServices component that fails to require authentication for a critical function (CWE-306). An unauthenticated attacker with network access can reach it over HTTP and fully compromise the product, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0.
Description
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network-reachable takeover of an identity management system, listed in CISA KEV with very high EPSS probability.
What it is
Oracle Fusion Middleware Identity Manager exposes a REST WebServices component that fails to require authentication for a critical function (CWE-306). An unauthenticated attacker with network access can reach it over HTTP and fully compromise the product, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0.
Impact
Successful exploitation results in complete takeover of Identity Manager, with high confidentiality, integrity and availability impact, giving the attacker control over an identity and access management system.
Attack surface
Reachable over the network via HTTP against the REST WebServices component; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-11-21 with a remediation due date of 2025-12-12, and EPSS gives a 30-day exploitation probability of 0.883 (99.8th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is documented.
What to do
- Apply the Oracle October 2025 Critical Patch Update for Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0) as the primary fix.
- If patching cannot be completed by the CISA due date, restrict network access to the Identity Manager REST WebServices endpoint to trusted hosts only.
- Follow CISA BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Review and rotate credentials and secrets held by Identity Manager in case of prior compromise.
Detection
- Monitor HTTP access logs for unauthenticated requests to Identity Manager REST WebServices endpoints, especially from unexpected source IPs.
- Alert on anomalous administrative or configuration changes within Identity Manager outside normal change windows.
- Hunt for new or modified accounts, tokens or policy changes in Identity Manager that were not initiated by known administrators.
- Correlate network connections to the Identity Manager REST interface with post-exploitation activity such as outbound callbacks or credential access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-61757 to the Known Exploited Vulnerabilities catalog on 21 November 2025 as "Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 December 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpuoct2025.html | Vendor Advisory |
| https://isc.sans.edu/diary/rss/32506 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61757 | US Government Resource |
Track CVE-2025-61757 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-61757), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.