Executive brief
Oracle Identity Manager is a critical identity and access management system used to manage user identities and permissions across enterprise systems. This vulnerability allows an unauthenticated attacker with network access to remotely take over the entire Identity Manager system without authentication, potentially exposing or compromising all managed identities and access credentials.
Technical details
An easily exploitable vulnerability in the Oracle Identity Manager Legacy UI component allows unauthenticated remote attackers to achieve complete system compromise via HTTP. The vulnerability requires no authentication, no special privileges, and no user interaction to exploit. Successful attacks result in full takeover of the Identity Manager instance, enabling attackers to read, modify, or delete identity data, manipulate access permissions, and disrupt identity management operations. Patches are expected to be available from Oracle.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed