Executive brief
Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a vulnerability in its legacy user interface. A low-privileged user could exploit this flaw to gain full control over the identity management system. Because this system controls access to other corporate resources, a successful attack could allow the intruder to compromise additional connected products and services.
Technical details
A vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is accessible via the network over HTTP and requires low-privileged authentication. While the attack complexity is rated as high, a successful exploit results in a scope change (S:C), meaning the impact extends beyond the Identity Manager itself to other products in the environment. The vulnerability allows for complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60330 by Oracle