Active Exploitation of Critical Vulnerability in Oracle Identity Manager
Oracle has released security updates to address a critical vulnerability in their Oracle Identity Manager.
Oracle has released security updates to address a critical vulnerability (CVE-2025-61757) in their Oracle Identity Manager. The vulnerability has a Common Vulnerability Scoring System (CVSSv3.1) score of 9.8 out of 10.
Successful exploitation of the authentication bypass vulnerability could allow a remote unauthenticated attacker to perform arbitrary code execution, privilege escalation, and move laterally across an organisation's core systems.
This vulnerability is reportedly being exploited in the wild.
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0.
Users and administrators of affected products are advised to update to the latest version immediately.
Indicators of Compromise
Possible indicators of compromise to support immediate detection, hunting, and containment:
HTTP POST requests to the following endpoint may also be indicative of attempted exploitation:
/iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
