Executive brief
A critical vulnerability exists in the Oracle Identity Manager Connector, a component used to integrate identity management services with various enterprise applications. A low-privileged attacker can exploit this flaw over the network to gain full control of the connector. Because this component manages identities across different systems, a successful attack could allow an intruder to compromise additional connected business applications and sensitive data.
Technical details
This vulnerability affects the Core component of Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0. It is classified as an easily exploitable flaw that allows a low-privileged attacker to gain unauthorized access via HTTP. The vulnerability is notable for a 'scope change' (S:C), meaning an exploit can impact resources beyond the security scope of the Identity Manager Connector itself, potentially leading to a full takeover of the component and its integrated systems. Confidentiality, integrity, and availability are all highly impacted. Users should refer to the Oracle July 2026 Critical Patch Update for remediation instructions.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published as part of Oracle Critical Patch Update