logo

Critical Flaw in Oracle Identity Manager Under Exploitation

ID: 10d5cb06-61a2-5641-b269-75e1dd419ebb

STIX ID: report--10d5cb06-61a2-5641-b269-75e1dd419ebb

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-11-24

Date Updated: 2026-04-21

Author: Rob Wright

...
...

A critical pre-authentication remote code execution vulnerability (CVE-2025-61757, CVSS 9.8) in Oracle Identity Manager was discovered by AssetNote/Searchlight Cyber researchers and is being actively exploited in the wild; the flaw—caused by an authentication-bypass related to Java filter and URI/matrix parameter handling (exploitable in some cases by adding a semicolon to URLs)—was patched by Oracle and added to CISA's Known Exploited Vulnerabilities catalog, and affected customers are urged to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.