CRITICAL

CVE-2025-61757

Oracle Identity Manager 2025-10-21 CVSS v3.1
CVSS
9.8
KEV

Description

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Summary dbcve.org

Oracle Identity Manager REST WebServices component contains an unauthenticated remote code execution vulnerability allowing complete system compromise via HTTP. Attackers can exploit this without any credentials or user interaction, achieving full confidentiality, integrity, and availability impact.

Mitigation

Apply Oracle Critical Patch Updates for the affected versions (12.2.1.4.0, 14.1.2.1.0) immediately. If patches are unavailable, restrict network access to Identity Manager REST endpoints via firewall or web application firewall until patch is applied.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

88.31%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE