Oracle Identity Manager RCE
- شناسه CVE: CVE-2025-61757
- شدت: بحرانی
- امتیاز CVSS: 9.8
- فروشنده/سازنده: Oracle
RCEOracleIdentity ManagerCISACritical
A critical Remote Code Execution vulnerability in Oracle Identity Manager (OIM) / Oracle Identity Governance, confirmed by CISA as actively exploited.
## Vulnerability Overview
Oracle Identity Manager is an enterprise identity management solution used for user provisioning, access management, and compliance. This vulnerability allows an unauthenticated attacker to execute arbitrary code on the OIM server through a Java deserialization flaw in the T3/IIOP protocol handler.
## Technical Details
- **Type:** Java Deserialization RCE (CWE-502)
- **Root Cause:** The T3 protocol listener in the WebLogic server underlying OIM deserializes untrusted Java objects. Known gadget chains (CommonsCollections, CommonsBeanutils) can be used to achieve arbitrary code execution.
- **Authentication:** None required — the T3 protocol is accessible without credentials.
- **Protocol:** T3 (TCP 7001) or IIOP
## Active Exploitation
- CISA has added this CVE to the Known Exploited Vulnerabilities catalog.
- Ransomware groups have been observed using this vulnerability for initial access.
- Estimated 5,000+ vulnerable OIM instances exposed to the internet.
## Impact
- Complete compromise of the identity management system
- Access to all user credentials and identity data
- Ability to create privileged accounts across connected systems
- Total domain compromise via identity federation
## Vulnerability Overview
Oracle Identity Manager is an enterprise identity management solution used for user provisioning, access management, and compliance. This vulnerability allows an unauthenticated attacker to execute arbitrary code on the OIM server through a Java deserialization flaw in the T3/IIOP protocol handler.
## Technical Details
- **Type:** Java Deserialization RCE (CWE-502)
- **Root Cause:** The T3 protocol listener in the WebLogic server underlying OIM deserializes untrusted Java objects. Known gadget chains (CommonsCollections, CommonsBeanutils) can be used to achieve arbitrary code execution.
- **Authentication:** None required — the T3 protocol is accessible without credentials.
- **Protocol:** T3 (TCP 7001) or IIOP
## Active Exploitation
- CISA has added this CVE to the Known Exploited Vulnerabilities catalog.
- Ransomware groups have been observed using this vulnerability for initial access.
- Estimated 5,000+ vulnerable OIM instances exposed to the internet.
## Impact
- Complete compromise of the identity management system
- Access to all user credentials and identity data
- Ability to create privileged accounts across connected systems
- Total domain compromise via identity federation
نرمافزارهای تحت تأثیر
- Oracle Identity Manager
- Oracle Identity Governance