By Carly Page
Publication Date: 2025-11-24 11:45:00
CISA has ordered US federal agencies to fix an actively exploited flaw in Oracle Identity Manager (OIM) within three weeks – a battle made more urgent by evidence that attackers may have abused the flaw months before a fix was released.
The error, tracked as CVE-2025-61757 and now I’m sitting in it CISA’s catalog of known exploited vulnerabilitiesis “easily exploitable” and allows an unauthenticated attacker with network access to compromise OIM, enabling a complete takeover of the system.
“Oracle Fusion Middleware contains a missing authentication for a critical functional vulnerability that allows unauthenticated remote attackers to take over Identity Manager,” CISA warned.
Authorities have been told they must close the vulnerability by December 12 or face standard federal compliance consequences.
…

