logo

Oracle Identity Manager Exploit Observation from September (CVE-2025-61757), (Thu, Nov 20th)

ID: 580d559e-d7b3-531a-b46d-03c324b8779f

STIX ID: report--580d559e-d7b3-531a-b46d-03c324b8779f

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2025-11-20

Date Updated: 2026-04-19

...
...

Searchlight Cyber disclosed CVE-2025-61757 in Oracle Identity Manager: appending ";.wadl" to endpoints bypasses authentication and can enable RCE. Oracle released a patch in the October CPU; log review found multiple pre-patch POST attempts to a vulnerable endpoint from different IPs using the same user-agent and a 556-byte payload (request bodies not captured). Early scans may have originated from Searchlight's research, but the observed activity constitutes scanning/exploitation attempts and includes actionable IOCs (IPs, user-agent, targeted URL).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.