Skip to main content

Oracle Products Multiple Vulnerabilities

Last Update Date: 24 Nov 2025 Release Date: 22 Oct 2025 8580 Views

RISK: Extremely High Risk

TYPE: Servers - Database Servers

TYPE: Database Servers

Multiple vulnerabilities were identified in Oracle Products, a remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, denial of service condition, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.

 

Note:

CVE-2025-61757 is being exploited in the wild. Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager, and trigger remote code execution on the targeted system. Hence, the risk level is rated as Extremely High Risk.

 

[Updated on 2025-11-24]

Updated Description, Risk Level and Related Links.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Elevation of Privilege
  • Data Manipulation

System / Technologies affected

  • Oracle MySQL
  • Java SE
  • Oracle Database Server
  • WebLogic Server
  • VirtualBox

For CVE-2025-61757:

  • Identity Manager: REST WebServices version 12.2.1.4.0, 14.1.2.1.0

 

 

For other Oracle products, please refer to the link below:

https://www.oracle.com/security-alerts/cpuoct2025.html


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

https://www.oracle.com/security-alerts/cpuoct2025.html


Vulnerability Identifier


Source


Related Link