This week’s release introduces a critical detection for CVE-2025-61757, a vulnerability in the Oracle Identity Manager REST WebServices component.
Key Findings
This flaw allows unauthenticated attackers with network access over HTTP to fully compromise the Identity Manager, potentially leading to a complete takeover.
Impact
Oracle Identity Manager (CVE-2025-61757): Exploitation could allow an unauthenticated remote attacker to bypass security checks by sending specially crafted requests to the application’s message processor. This enables the creation of arbitrary employee accounts, which can be leveraged to modify system configurations and achieve full system compromise.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | fa584616fe2241608cb8bd1339fdbe7e | N/A | Oracle Identity Manager – Pre-Auth RCE – CVE:CVE-2025-61757 | N/A | Block | This is a new detection. |
Source: Cloudflare
Latest Posts
- Amazon Redshift Serverless now maintains datashare permissions during restore

- OpenSearch OR2 and OM2 instances in AWS GovCloud (US-East, US-West) Regions

- Amazon EC2 R8g instances now available in additional regions

- (Updated) Microsoft Teams Copilot without transcription becomes default for meetings – conversation history now persists [MC1139493]
![(Updated) Microsoft Teams Copilot without transcription becomes default for meetings - conversation history now persists [MC1139493] 5 pexels pixabay 415574](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)




![(Updated) Microsoft Teams Copilot without transcription becomes default for meetings - conversation history now persists [MC1139493] 5 pexels pixabay 415574](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-415574-150x150.webp)
