Executive brief
Oracle Identity Manager, a tool used by organizations to manage user identities and access rights, contains a critical security flaw in its legacy user interface. An unauthorized person can exploit this over the internet to gain full access to sensitive identity data. This could allow an attacker to view, change, or delete critical user information and system permissions, potentially leading to a total compromise of the organization's identity management system.
Technical details
A vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager (part of Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for unauthorized access to, or the creation, deletion, and modification of, all data accessible by Oracle Identity Manager. The vulnerability has a CVSS 3.1 base score of 9.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published