漏洞描述 Oracle Identity Manager 是 Oracle 提供的一款身份管理解决方案。该漏洞存在于 /iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl 接口中,攻击者可以通过发送特制的 Groovy 脚本,利用命令执行漏洞在目标服务器上执行任意命令,可能导致敏感信息泄露、系统被完全控制等严重后果。
相关漏洞推荐 POC oracle-ebs-sqllog-exposure: Oracle EBS SQL Log - Exposure POC wp-duracelltomi-google-tag-manager-fpd: WordPress Plugin Google Tag Manager - Full Path Disclosure ETAP Safety Manager 跨站脚本漏洞 POC CVE-2020-26836: SAP Solution Manager - Open Redirect POC CVE-2021-2135: Oracle WebLogic Server - Remote Code Execution POC bitrix-log-file-disclosure: Bitrix Site Manager - Log File Disclosure POC nexus-repository-anonymous-access: Nexus Repository Manager - Anonymous Access Enabled POC CVE-2019-25213: WordPress Advanced Access Manager - Path Traversal POC aem-anonymous-write: Adobe Experience Manager (AEM) - Anonymous JCR Node Creation 中成科信票务管理系统 /SystemManager/Api/TicketManager.ashx SQL 注入漏洞 新视窗新一代物业管理系统 /OfficeManagement/RegisterManager/Report/Training/Report/GetprintData.asmx SQL 注入漏洞 Oracle Identity Manager 访问控制不当漏洞 POC CVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication Bypass