Executive brief
Oracle Identity Manager is a critical enterprise system that manages user identities and access control for corporate networks and applications. A vulnerability in the legacy web interface allows unauthenticated attackers to trick authorized users into performing unauthorized actions—such as creating or deleting user accounts or accessing sensitive identity data—without requiring a password or direct access to the system. This could lead to account compromise, unauthorized privilege escalation, or data theft affecting thousands of employees.
Technical details
The vulnerability exists in the OIM Legacy UI component and is exploitable via HTTP without authentication, but requires user interaction (such as clicking a malicious link). The attack vector is network-based and affects the confidentiality and integrity of data. An unauthenticated attacker can craft a malicious request that, when clicked by a legitimate user, results in unauthorized creation, deletion, or modification of critical identity data or access to sensitive information within Oracle Identity Manager. The vulnerability is present in versions 12.2.1.4.0 and 14.1.2.1.0. Patches may be available through Oracle's security advisory channels.
Affected products
- Oracle Identity Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed