Oracle Products Multiple Vulnerabilities
RISK: Extremely High Risk
TYPE: Servers - Database Servers

Multiple vulnerabilities were identified in Oracle Products, a remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, denial of service condition, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.
Note:
CVE-2025-61757 is being exploited in the wild. Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager, and trigger remote code execution on the targeted system. Hence, the risk level is rated as Extremely High Risk.
[Updated on 2025-11-24]
Updated Description, Risk Level and Related Links.
Impact
- Denial of Service
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
- Elevation of Privilege
- Data Manipulation
System / Technologies affected
- Oracle MySQL
- Java SE
- Oracle Database Server
- WebLogic Server
- VirtualBox
For CVE-2025-61757:
- Identity Manager: REST WebServices version 12.2.1.4.0, 14.1.2.1.0
For other Oracle products, please refer to the link below:
https://www.oracle.com/security-alerts/cpuoct2025.html
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
https://www.oracle.com/security-alerts/cpuoct2025.html
Vulnerability Identifier
Source
Related Link
Related Tags
Share with
