Application Security von Cloudflare
WAF-Erkennung für Oracle Identity Manager
Eine neue WAF-Regel erkennt Angriffe auf die kritische Schwachstelle CVE-2025-61757 im Oracle Identity Manager und blockiert diese.
This week’s release introduces a critical detection for CVE-2025-61757, a vulnerability in the Oracle Identity Manager REST WebServices component.
Key Findings
This flaw allows unauthenticated attackers with network access over HTTP to fully compromise the Identity Manager, potentially leading to a complete takeover.
Impact
Oracle Identity Manager (CVE-2025-61757): Exploitation could allow an unauthenticated remote attacker to bypass security checks by sending specially crafted requests to the application's message processor. This enables the creation of arbitrary employee accounts, which can be leveraged to modify system configurations and achieve full system compromise.
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
Comments
Cloudflare Managed Ruleset
...39fdbe7e
N/A
Oracle Identity Manager - Pre-Auth RCE - CVE:CVE-2025-61757
N/A
Block
This is a new detection.