
Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.
This post-incident report examines the 2025 supply chain breach targeting Oracle Cloud’s identity and authentication infrastructure. It details how threat actors exploited an unpatched pre-authentication Remote Code Execution vulnerability (CVE-2021-35587, CVSS 9.8) in legacy Oracle Access Manager (OAM) instances to forge authentication tokens and operate undetected for months. The report evaluates the blast radius—which impacted over 140,000 tenants and exposed 6 million user records—conducts a root-cause analysis on legacy asset exposure, and outlines immediate token revocation, short-term SIEM enhancement, and long-term Zero Trust security recommendations.