Executive brief
A critical vulnerability exists in the Oracle Identity Manager Connector, a tool used to manage user identities and access across mainframe systems. A low-privileged user could exploit this flaw over the network to take full control of the connector. This could lead to unauthorized access to sensitive corporate data and potentially allow the attacker to compromise other connected business systems.
Technical details
A vulnerability in the Mainframe Connectors component of Oracle Identity Manager Connector (part of Oracle Fusion Middleware) is classified as Improper Access Control (CWE-284). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. A successful exploit allows the attacker to compromise and take over the Identity Manager Connector. Due to a scope change (Status: Changed), the impact can extend beyond the connector itself to other integrated products, affecting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle released the security alert.