Executive brief
A vulnerability exists in Oracle Identity Manager, a tool used by organizations to manage user identities and access rights. An attacker could exploit this flaw to gain unauthorized access to sensitive data or modify user information without needing a username or password. This could lead to unauthorized data changes or the exposure of internal identity records.
Technical details
An improper access control vulnerability (CWE-284) exists in the End User Self Service component of Oracle Identity Manager. The flaw is exploitable by an unauthenticated attacker with network access via the Internet Inter-ORB Protocol (IIOP). Successful exploitation allows the attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of data managed by Identity Manager. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published security alert cspujun2026.html