https://reddit.com/r/netsec/comments/1p1siyi/breaking_oracles_identity_manager_preauth_rce/: Breaking Oracle’s Identity Manager: Pre-Auth RCE (CVE-2025-61757)
Published Nov 20, 2025
·Updated
Affected Software
1 affected component
Oracle Identity Manager
Frequently Asked Questions
1
What is the severity of CVE-2025-61757?
CVE-2025-61757 has been rated as critical due to the potential for pre-authentication remote code execution.
2
How do I fix CVE-2025-61757?
To mitigate CVE-2025-61757, update Oracle Identity Manager to the latest patched version provided by Oracle.
3
What systems are affected by CVE-2025-61757?
CVE-2025-61757 specifically affects Oracle Identity Manager deployments that are configured with vulnerable settings.
4
What attack vectors exist for CVE-2025-61757?
CVE-2025-61757 can be exploited via unauthenticated network requests that trigger remote code execution.
5
Is there a workaround for CVE-2025-61757?
While there may be temporary mitigations, the recommended action is to apply the official patch provided by Oracle as the best long-term solution.