Drooid Logo
Back to story perspectives

Full Breakdown

Critical Vulnerability in Oracle Identity Manager Exposes Enterprises to Remote Code Execution

11/22/2025, 8:17:09 PM

Overview of the Vulnerability

A critical vulnerability in Oracle Identity Manager (OIM), tracked as CVE-2025-61757, has been disclosed by Searchlight Cyber researchers Adam Kues and Shubham Shah. This flaw allows for remote code execution (RCE) without authentication, posing a significant risk to organizations utilizing OIM for identity and credentials management. The vulnerability was originally patched by Oracle on October 21, 2025, and has been assigned a critical CVSS score of 9.8.

Technical Details and Exploitation Potential

The vulnerability exploits an authentication bypass weakness, enabling attackers to manipulate authentication flows and escalate privileges. By using a crafted URL ending in “;.wadl,” an unauthenticated user can access the groovyscriptstatus endpoint, which compiles Groovy scripts without executing them. This method allows attackers to leverage Java’s annotation processor to execute Groovy annotations at compile time. Searchlight Cyber indicated that the flaw is "easily exploitable by threat actors," potentially leading to the breach of servers handling personally identifiable information (PII) and user credentials.

Evidence of Prior Exploitation Attempts

According to Johannes Ullrich, founder of the SANS Internet Storm Center, there were indications of potential exploitation attempts prior to the public disclosure of the vulnerability. Between August 30 and September 9, 2025, multiple IP addresses scanned for the vulnerable endpoint, suggesting that the activity was likely conducted by attackers rather than researchers. Ullrich noted that these IPs had also targeted other vulnerabilities, including Liferay CVE-2025-4581 and Log4j.

Official Responses and Recommendations

In response to the critical nature of CVE-2025-61757, Oracle's Critical Patch Update Advisory for October 2025 urged customers to apply the security patches immediately. The advisory emphasized that exploitation of this vulnerability could compromise the confidentiality, integrity, and availability of systems, potentially leading to a complete takeover of the Identity Manager.

Clarification on Exploitation Activity

Shubham Shah from Searchlight Cyber clarified that the scanning activity reported by SANS was part of their research efforts into the vulnerability and not indicative of malicious exploitation. Shah confirmed that the same IP addresses used in the scans were part of their notification process to affected organizations.

Conclusion and Implications

The disclosure of CVE-2025-61757 highlights the ongoing security challenges faced by organizations using Oracle Identity Manager. With the potential for significant exploitation, it is crucial for enterprises to implement the recommended patches promptly to mitigate risks associated with this vulnerability. The incident underscores the importance of vigilance in cybersecurity practices, particularly in the face of evolving threats targeting critical infrastructure.