Summary
CVE-2025-61757 is a critical pre-authentication vulnerability in Oracle Fusion Middleware's Identity Manager REST WebServices. A network-accessible attacker can bypass REST authentication by appending specific suffixes to REST URIs, reach a protected Groovy script endpoint, and trigger remote code execution, potentially taking over Identity Manager. Patches were released in Oracle's October 2025 CPU, and exploitation has been observed in the wild per credible threat intel and government advisories.
Why Planned Fix?
2/6Exploitation Details
Full takeover of Oracle Identity Manager; remote code execution; privilege escalation; manipulation of identities and provisioning workflows.
Affected Software
| Product | Affected Versions |
|---|---|
| Identity Manager | 12.2.1.4.0, 14.1.2.1.0 |
Oracle Fusion Middleware Identity Manager (OIM) is an enterprise identity management system that automates provisioning, access governance, and lifecycle management for users across enterprise resources.
Affected ComponentREST WebServices component of Oracle Identity Manager (OIM) within Oracle Fusion Middleware.
REST WebServices component of Oracle Identity Manager (OIM) within Oracle Fusion Middleware.
Affected Endpoints(2)/iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl, /iam/governance/applicationmanagement/templates;.wadl…
Not available
Not available
Not available
Probability of exploitation in the next 30 days
Worse than 84% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (2)
- •cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
- •cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | https://nvd.nist.gov/vuln/detail/CVE-2025-61757 |
| www.oracle.com | https://www.oracle.com/security-alerts/cpuoct2025.html |
| www.oracle.com | https://www.oracle.com/security-alerts/cpuoct2025verbose.html |
| horizon3.ai | https://horizon3.ai/attack-research/vulnerabilities/cve-2025-61757/ |
| fidelissecurity.com | https://fidelissecurity.com/vulnerabilities/cve-2025-61757/ |
| www.ionix.io | https://www.ionix.io/blog/cve-2025-61757-oracle-identity-manager/ |
| www.purple-ops.io | https://www.purple-ops.io/resources-hottest-cves/oracle-zero-day-cve-2025-61757/ |
| www.cisa.gov | https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61757 |
| isc.sans.edu | https://isc.sans.edu/diary/rss/32506 |
| advisories.ncsc.nl | https://advisories.ncsc.nl/2025/ncsc-2025-0334-1.pdf |
| slcyber.io | https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/ |
| www.securityweek.com | https://www.securityweek.com |
Priority History
Initial analysis