Executive brief
Oracle Identity Manager is a critical identity and access management system used to manage user accounts, roles, and permissions across enterprise applications. This vulnerability allows an attacker with only network access to completely compromise the system without any credentials, potentially granting unauthorized access to all managed identities and systems. An exploit could result in complete takeover of identity management infrastructure, enabling attackers to create backdoor accounts, modify user permissions, or access sensitive employee and customer data.
Technical details
This is an unauthenticated remote code execution or privilege escalation vulnerability in the Core component of Oracle Identity Manager (OIM). The vulnerability is easily exploitable through the HTTP protocol and requires no user interaction or authentication. An attacker with network access can send a crafted HTTP request to compromise the system. Successful exploitation results in complete system compromise with impact to confidentiality, integrity, and availability. The vulnerability affects OIM versions 12.2.1.4.0 and 14.1.2.1.0; patch availability should be confirmed through Oracle security updates.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed