Threat Intelligence / CVE / CVE-2025-61757
CVE-2025-61757
CISA KEVVulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-306
Threats tracking this CVE
References
- https://www.oracle.com/security-alerts/cpuoct2025.html
- https://isc.sans.edu/diary/rss/32506
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61757
Full detection coverage & IOCs for threats exploiting CVE-2025-61757 are available via the Threadlinqs MCP server (Purple tier). View plans →