CVE-2025-61757: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
Other sources
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services to mitigate exposure of Oracle Identity Manager (Identity Manager REST WebServices) in cloud deployments.
- Compensating control
Discontinue use of the product if mitigations are unavailable: stop using Oracle Identity Manager (Oracle Fusion Middleware Identity Manager component) until an effective mitigation or fix is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61757?
CVE-2025-61757 is classified as a high-severity vulnerability due to its potential for unauthenticated remote exploitation.
How do I fix CVE-2025-61757?
To mitigate CVE-2025-61757, Oracle recommends applying the latest security patches for affected versions of Oracle Identity Manager.
Which versions of Oracle Identity Manager are affected by CVE-2025-61757?
CVE-2025-61757 affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0.
Can CVE-2025-61757 be exploited remotely?
Yes, CVE-2025-61757 can be easily exploited by an unauthenticated attacker with network access via HTTP.
What component does CVE-2025-61757 affect?
CVE-2025-61757 specifically affects the REST WebServices component of Oracle Identity Manager.