Executive brief
Oracle Identity Manager, a tool used by organizations to manage user access and digital identities, contains a critical security flaw in its legacy user interface. An unauthorized attacker can exploit this over the network to gain full control of the system. This could lead to a total compromise of user credentials, unauthorized access to sensitive corporate resources, and significant operational disruption.
Technical details
A critical vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager. The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. Successful exploitation allows for a complete takeover of the Oracle Identity Manager instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60329 by Oracle