[CIVN-2025-0345] Remote Code Execution Vulnerability in Oracle Identity Manager

By Published On: November 27, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in Oracle Identity Manager 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Oracle Identity Manager Versions 12.2.1.4.0 and 14.1.2.1.0
Overview
A vulnerability has been reported in Oracle Identity Manager which could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system.
Target Audience:
All end-user organizations and individuals using Oracle Identity Manager.
Risk Assessment:
High risk of sensitive data disclosure and system compromise.
Impact Assessment:
Potential for remote code execution and system compromise.
Description
Oracle Identity Manager (OIM) is an enterprise identity and access governance solution that automates provisioning, password management, and compliance-driven access reviews.
This vulnerability exists in Oracle Identity Manager due to an authentication bypass flaw in Oracle Identity Managers REST APIs.
Successful exploitation of this vulnerability could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system.
Note: CVE-2025-61757 is being actively exploited in the wild.
 
Solution
Apply appropriate updates as mentioned in:
https://www.oracle.com/security-alerts/cpuoct2025.html
Vendor Information
Oracle
https://www.oracle.com/security-alerts/cpuoct2025.html
References
Oracle
https://www.oracle.com/security-alerts/cpuoct2025.html
CVE Name
CVE-2025-61757
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmkoUjgACgkQ3jCgcSdc
ys9i/g/8D1O4sq/zqLneGlBI7c0kxEnyB1pacZTu/CcdtCs//pLDpYUQBfCAFpam
ApjY+FXAerdbvHvOB+c7V1eN84I1kqieQU9vk+tVfp6zBATL6mZOzdwd6RKtQuCw
90PS9QxgfnZ/ywog+iDcbYFIU7oCv1mMCDUuCEee/ykbnOsQqKdlphv180/srK/3
tziv4X45CUAbDkS/jTvoeJf7ogC2uHg+xM47nZN/pLJOcJApeVU6A5n8NUr9CMTd
dvN8oDaLogYqS8I3jwDYSXFUGkorDvc92VoBoQouS/2xg/TSm2P7Yya/UFf0B8m+
sdbZlVEZxxdGNC/bR6PCLYQt2i+RsOkN25ht3h7tx9fQy2B8K/gJ3L4U/fHoRtxB
7HxuwuGxgK8rSqmgJo093vVRs3U+Jh+Ug9/r1ew+nDmVuscK8Q7AEhRUHpUkShGS
lj+mRSsobbzzclkQzkUBGEoO6Sr/G6FoeIyqICxyiNZmkApa/xGwy4goi6WkAmKb
bgV6CdsoMqiCHaUYTv915EAtsV6Dc/Fugo+LBc0d5DARm88bR4hHLYXTKhDi9AoA
waH5t7Prx5SPgFU+LX+YDWWteFuCIVadxyiz/S42cCFU9H+DD5qxu1ErFhmZk+fn
wOn5wLvJaRQJN7y7U2P7Ic8r/MDbO8zzJkCTCeKdfJvKoTPDUuk=
=q/1/
—–END PGP SIGNATURE—–

Share this article