Site icon VMVirtualMachine.com

CISA warns that the RCE flaw in Oracle Identity Manager is being actively exploited

CISA warns that the RCE flaw in Oracle Identity Manager is being actively exploited

By Lawrence Abrams
Publication Date: 2025-11-21 23:50:00

The US Cybersecurity & Infrastructure Security Agency (CISA) is warning government agencies to patch an Oracle Identity Manager known as CVE-2025-61757 that has been exploited in attacks, possibly as a zero-day.

CVE-2025-61757 is an RCE pre-authentication vulnerability in Oracle Identity Manager discovered and disclosed by Searchlight Cyber ​​analysts Adam Kues and Shubham Shahflaw.

The flaw is due to an authentication bypass in the Oracle Identity Manager REST APIs where a security filter can be tricked into treating protected endpoints by appending parameters such as “publicly accessible”. ?WSDL or ;.wadl to URL paths.

Once unauthenticated access occurs, attackers can access a Groovy script, which is a compilation endpoint that does not normally execute a script. However, it can be abused to execute malicious code via Groovy’s compile-time annotation processing capabilities.

This chain of errors allowed researchers to achieve remote pre-authentication…

Exit mobile version