Identity Manager - CVE-2025-61757
Background
[oracle@oimms oracle]$ cat idm/server/apps/oim.ear/META-INF/application.xml
... snip ...
<module>
<web>
<web-uri>applicationrest.war</web-uri>
<context-root>iam/governance/applicationmanagement</context-root>
</web>
</module>[oracle@oimms oracle]$ find . -type f -name "applicationrest.war"
./idm/server/apps/oim.ear/applicationrest.war
kpen :: ~/oracle/tmp » docker container cp oimms:/u01/oracle/idm/server/apps/oim.ear/applicationrest.war .


POC || GTFO
Auth Bypass
RCE + Exfil

Resources
Last updated