Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle Identity Manager Legacy UI component of Oracle Fusion Middleware and is caused by improper access control and authentication weaknesses (CWE-306). It permits an unauthenticated attacker with network connectivity to the T3 or IIOP services to gain full control over the Oracle Identity Manager instance. Successful exploitation results in a complete takeover, with full loss of confidentiality, integrity, and availability of the system and its data.

Affected Systems

Affected products are Oracle Identity Manager version 12.2.1.4.0 and 14.1.2.1.0. No other versions or products are listed as affected.

Risk and Exploitability

The CVSS base score of 9.8 indicates critical severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; no credentials, privileges, or user interaction are required beyond establishing a connection to the vulnerable T3/IIOP ports.

Generated by OpenCVE AI on August 4, 2026 at 04:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that fixes the Oracle Identity Manager Legacy UI vulnerability or upgrade to a non‑affected version.
  • Configure network controls to limit access to the T3 and IIOP ports to trusted IPs or a VPN, blocking external exposure.
  • If a patch or upgrade is not immediately available, secure the OIM instance by disabling the Legacy UI interface or blocking the T3/IIOP services through firewall or router rules.
  • Secure the Legacy UI by requiring authentication and ensuring no anonymous access is allowed; if this cannot be ensured, disable the Legacy UI or enforce strict access controls.

Generated by OpenCVE AI on August 4, 2026 at 04:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Oracle Identity Manager Legacy UI

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Oracle Identity Manager Legacy UI

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Identity Manager via T3/IIOP
Weaknesses CWE-284
CWE-732

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Identity Manager via T3/IIOP
Weaknesses CWE-284
CWE-732

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:57.264Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60329

cve-icon Vulnrichment

Updated: 2026-07-23T19:40:29.064Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function