LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-61757: Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 21, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 12, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-61757 to its Known Exploited Vulnerabilities catalog on Nov 21, 2025, with a federal patch deadline of Dec 12, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.

CVE-2025-61757 is a missing authentication for critical function vulnerability in Oracle Fusion Middleware. It allows unauthenticated remote attackers to take over Identity Manager. For organizations running this middleware stack, especially those relying on its identity services, the issue matters because it can give an external attacker control over a core identity component without any credentials. Confirm all product-specific details against the vendor advisory.

CISA notes that the flaw enables takeover of Identity Manager and requires applying mitigations per vendor instructions, following applicable BOD 22-01 guidance for cloud services, or discontinuing use if mitigations are unavailable. Known ransomware use is not documented.

How it works

This vulnerability falls under CWE-306, Missing Authentication for Critical Function. In products of this class, a critical operation—here related to Identity Manager within Oracle Fusion Middleware—can be reached and exercised without the expected authentication checks. An unauthenticated remote attacker who can reach the affected interface or endpoint can invoke that function and thereby gain control of Identity Manager.

Exact request formats, parameters, or attack sequences are not provided in the public summary; treat any such details as requiring confirmation against the vendor advisory. The practical risk is that the attacker obtains administrative or equivalent control over identity management capabilities without first authenticating, which can cascade into broader access within the environment that depends on that identity service.

Am I affected? How to find it in your systems

Oracle Fusion Middleware commonly appears in enterprise application platforms, identity and access management deployments, and integration layers that sit between web applications and backend services. Identity Manager components are typically part of larger Oracle identity suites used for provisioning, authentication, and authorization.

How to remediate

Patch first. Apply the vendor update or mitigation named in the Oracle advisory for CVE-2025-61757. Follow the vendor’s installation and verification steps exactly, then re-test that the critical Identity Manager functions now enforce authentication as expected.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a missing-authentication flaw on a critical identity function.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full compromise of identity systems and subsequent data exposure or lateral movement. If you have evidence of exploitation or cannot rule it out, treat the incident as a potential breach: isolate affected systems, preserve logs, and follow your incident-response and notification procedures. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information associated with your organization have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · Fusion Middleware
WeaknessCWE-306
Added to CISA KEVNov 21, 2025
Federal patch deadlineDec 12, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities