Executive brief
Oracle Identity Manager Connector is a component of Oracle Fusion Middleware used to manage user identities and access across enterprise systems. An unauthenticated attacker with network access can exploit a vulnerability to gain unauthorized access to sensitive identity data without authentication. Successful exploitation could expose critical customer and operational data managed by the identity system.
Technical details
An easily exploitable vulnerability in Oracle Identity Manager Connector (Core component) allows unauthenticated network attackers to bypass access controls via HTTP requests. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. Successful exploitation results in unauthorized read access to sensitive data, with potential scope change affecting other Oracle Fusion Middleware products. No user interaction or elevated privileges are required for exploitation. Patch availability and remediation guidance should be obtained from Oracle's security advisories.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed