Oracle Identity Manager Exploit Observation from September (CVE-2025-61757), (Thu, Nov 20th)
ID: 580d559e-d7b3-531a-b46d-03c324b8779f
STIX ID: report--580d559e-d7b3-531a-b46d-03c324b8779f
Feed Name: SANS ISC Diary
Searchlight Cyber disclosed CVE-2025-61757 in Oracle Identity Manager: appending ";.wadl" to endpoints bypasses authentication and can enable RCE. Oracle released a patch in the October CPU; log review found multiple pre-patch POST attempts to a vulnerable endpoint from different IPs using the same user-agent and a 556-byte payload (request bodies not captured). Early scans may have originated from Searchlight's research, but the observed activity constitutes scanning/exploitation attempts and includes actionable IOCs (IPs, user-agent, targeted URL).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
