Site icon VMVirtualMachine.com

CISA urgently requests a fix for an actively exploited vulnerability in Oracle Identity Manager

CISA urgently requests a fix for an actively exploited vulnerability in Oracle Identity Manager

By Infosecurity Magazine
Publication Date: 2025-11-24 11:00:00

According to the US Cybersecurity and Infrastructure Security Agency (CISA), a critical vulnerability is being exploited in Oracle Identity Manager.

The error, tracked as CVE-2025-61757Was revealed by Searchlight Cyber on November 20th

This was reported by Oracle on November 21st added added to the CISA Known Exploited Vulnerabilities (KEV) catalog on the same day after active exploitation was reported.

The vulnerability lies in the REST WebServices component of Identity Manager, part of the Oracle Fusion Middleware.

It allows unauthenticated remote attackers with network access over HTTP to execute arbitrary code on affected systems (versions 12.2.1.4.0 and 14.1.2.1.0) and could lead to Oracle Identity Manager takeover.

It has been assigned a CVSS of 9.8, meaning the vulnerability is critical.

This vulnerability poses a serious risk because exploitation does not require prior credentials or system access.

The simple authentication bypass paired…

Exit mobile version