Description
Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Mainframe Connectors). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker who can reach the Oracle Identity Manager Connector over HTTP to take full control of the component. The flaw resides in the Mainframe Connectors of the Identity Manager Connector product. Exploitation leads to complete confidentiality, integrity, and availability compromise of the affected service, potentially propagating further impact to other Oracle Fusion Middleware products whose scope may be altered. The weakness results in uncontrolled execution and takeover of the connector.

Affected Systems

Oracle Corporation’s Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These are part of the Oracle Fusion Middleware stack and are reachable via standard HTTP interfaces.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. The EPSS score is below 1 % but not zero, meaning exploitation is unlikely at this time but could occur if attackers mount a targeted campaign. The vulnerability is not listed in CISA’s KEV catalog, yet the high impact and low‑privilege attack vector make it a priority for remediation. An attacker only needs network access to the HTTP endpoint, minimal privileges, and the ability to send crafted requests to successfully compromise the service.

Generated by OpenCVE AI on June 17, 2026 at 18:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses CVE-2026-35294 for the impacted connector versions.
  • If a patch is not yet available, restrict HTTP access to the Identity Manager Connector by firewalling or VLAN segmentation to prevent external network reachability.
  • Continuously monitor audit and access logs for unauthorized or anomalous HTTP traffic to the connector service.

Generated by OpenCVE AI on June 17, 2026 at 18:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Mainframe Connectors). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:21:47.195Z

Reserved: 2026-04-01T20:03:40.836Z

Link: CVE-2026-35294

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:30:02Z

Weaknesses

No weakness.