CVE-2025-61757 is a critical vulnerability in the REST WebServices component of Oracle Identity Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable flaw allows unauthenticated attackers with network access via HTTP to fully compromise the Identity Manager, leading to complete takeover with severe impacts on confidentiality, integrity, and availability. With a CVSS v3.1 score of 9.8, this vulnerability is actively exploited in the wild, as confirmed by CISA and evidenced by available Nuclei templates for authentication bypass. The high EPSS score, FAUCET Risk Score of 100/100, and extensive media coverage and community discussion underscore its critical nature and the urgency for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:* | ||
14.1.2.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.