Skip to content

Oracle exploit: IAM under attack

Ye Olde Fashioned authentication filters in a Groovy codebase to blame.

Oracle exploit: IAM under attack
Image credit: https://unsplash.com/@simmerdownjpg

Customers running Oracle’s Identity Manager (OIM) software are exposed to a critical pre-auth RCE vulnerability that is being actively exploited.

Per CVE.org: CVE-2025-61757 (CVSS 9.8) is an “easily exploitable vulnerability [that] allows unauthenticated attacker with network access via HTTP to compromise Identity Manager [for] takeover of Identity Manager.”

It stems from the use of “very error-prone” authentication filters in its Apache Groovy/Java codebase that are “almost always bypassable” according to the researchers credited by Oracle with the vulnerability disclosure. 

This content is for members only

Subscribe
Add The Stack on Google