Executive brief
Oracle Identity Manager is a critical component of Oracle Fusion Middleware used to manage user identities and access across enterprise systems. An attacker with low-level network access can exploit this vulnerability to gain full administrative control over the system, potentially compromising sensitive identity data, modifying access controls, and disrupting identity management operations across connected applications.
Technical details
This is an easily exploitable privilege escalation vulnerability in the Core component of Oracle Identity Manager. The vulnerability allows a low-privileged attacker with network access via HTTP (no special authentication beyond basic user privileges) to achieve full system compromise. The attack requires no user interaction and can result in complete takeover of Oracle Identity Manager, affecting both confidentiality and integrity of identity management data. Affected versions are 12.2.1.4.0 and 14.1.2.1.0; patch availability should be verified through Oracle's official security advisories.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed