← Vulnerability feed

Vulnerability record · CVE-2025-61757 · published 21 October 2025

CVE-2025-61757: Oracle Identity Manager REST WebServices missing authentication allows takeover

Oracle · Identity Manager

Oracle Fusion Middleware Identity Manager exposes a REST WebServices component that fails to require authentication for a critical function (CWE-306). An unauthenticated attacker with network access can reach it over HTTP and fully compromise the product, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0.

9.8 CVSS 3.1 Critical CISA KEV since 21 Nov 2025 EPSS 89% · top 0.2% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score
89%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network-reachable takeover of an identity management system, listed in CISA KEV with very high EPSS probability.

What it is

Oracle Fusion Middleware Identity Manager exposes a REST WebServices component that fails to require authentication for a critical function (CWE-306). An unauthenticated attacker with network access can reach it over HTTP and fully compromise the product, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0.

Impact

Successful exploitation results in complete takeover of Identity Manager, with high confidentiality, integrity and availability impact, giving the attacker control over an identity and access management system.

Attack surface

Reachable over the network via HTTP against the REST WebServices component; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-11-21 with a remediation due date of 2025-12-12, and EPSS gives a 30-day exploitation probability of 0.883 (99.8th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is documented.

What to do

  • Apply the Oracle October 2025 Critical Patch Update for Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0) as the primary fix.
  • If patching cannot be completed by the CISA due date, restrict network access to the Identity Manager REST WebServices endpoint to trusted hosts only.
  • Follow CISA BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
  • Review and rotate credentials and secrets held by Identity Manager in case of prior compromise.

Detection

  • Monitor HTTP access logs for unauthenticated requests to Identity Manager REST WebServices endpoints, especially from unexpected source IPs.
  • Alert on anomalous administrative or configuration changes within Identity Manager outside normal change windows.
  • Hunt for new or modified accounts, tokens or policy changes in Identity Manager that were not initiated by known administrators.
  • Correlate network connections to the Identity Manager REST interface with post-exploitation activity such as outbound callbacks or credential access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-61757 to the Known Exploited Vulnerabilities catalog on 21 November 2025 as "Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 December 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-61757 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2017-10151Oracle identity manager vulnerabilityVulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affec…EPSS 3.9%9.9CVE-2026-61066Oracle identity manager improper access control vulnerabilityVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are…EPSS 0.43%9.9CVE-2026-60720Oracle identity manager missing authentication for critical function vulnerabilityVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are…EPSS 0.43%9.9CVE-2026-35294Oracle identity manager improper access control vulnerabilityVulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Mainframe Connectors). Supported versions that are af…EPSS 0.43%9.9CVE-2026-35268Oracle identity manager improper access control vulnerabilityVulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and …EPSS 0.43%9.9CVE-2017-3553Oracle identity manager vulnerabilityVulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Rules Engine). The supported version that is affect…EPSS 2.4%9.8CVE-2026-83042Oracle identity manager improper authentication vulnerabilityVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are…EPSS 0.51%9.8CVE-2026-70913Oracle identity manager improper authentication vulnerabilityVulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2025-61757), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.