Executive brief
Oracle Identity Manager, a tool used to manage user identities and access rights across an organization, contains a security vulnerability in its REST WebServices component. An unauthorized person can exploit this over the network to modify, create, or delete sensitive identity data without needing a password. This could lead to unauthorized access changes or the corruption of critical user directories and security records.
Technical details
An improper access control vulnerability (CWE-284) exists in the REST WebServices component of Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized creation, deletion, or modification of data accessible to Identity Manager. While the vulnerability impacts data integrity, it does not directly result in the exposure of confidential information or a loss of service availability (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory