Executive brief
Oracle Identity Manager is a widely deployed identity and access management system used to control who can access corporate applications and data. A flaw in its Legacy UI component allows an authenticated attacker on the network to escalate privileges and take complete control of the Identity Manager instance, compromising confidentiality, integrity, and availability of identity services.
Technical details
The vulnerability exists in the OIM Legacy UI component of Oracle Identity Manager and can be exploited by a low-privileged, authenticated attacker with network access via HTTP. The vulnerability is easily exploitable (no complex exploitation techniques required) and does not require user interaction. Successful exploitation results in full compromise of the Identity Manager instance, granting the attacker unauthorized control over identity and access management functions. The vulnerability affects Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0. Patch availability has not been confirmed in the provided advisory text.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed