Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Identity Manager legacy user interface allows an attacker with low privileged credentials and network connectivity over HTTP to gain full control of the service. The vulnerability involves improper authorization and lack of proper privilege checks, enabling the attacker to potentially modify, delete, or exfiltrate data and disrupt service availability. Due to changes in scope, a successful compromise may also affect additional products within the Oracle Fusion Middleware stack.

Affected Systems

The affected versions are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, which are deployed as part of Oracle Fusion Middleware and accessed through standard HTTP endpoints.

Risk and Exploitability

With a CVSS base score of 8.5, the flaw is considered high severity, affecting confidentiality, integrity, and availability. The EPSS score of less than 1% indicates low likelihood of exploitation at present, but the potential impact remains high. The vulnerability is not present in the CISA KEV catalog. Exploitation requires network access to the HTTP interface and an existing low‑privileged user account; once authenticated, the attacker can take over the entire service.

Generated by OpenCVE AI on August 4, 2026 at 04:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Identity Manager patch or upgrade to a non‑vulnerable release
  • Restrict HTTP access to trusted internal networks or enforce VPN tunnels to limit exposure
  • Disable or remove low‑privileged user accounts from accessing the legacy UI, ensuring only privileged accounts can reach the service
  • Monitor audit logs and enforce strict access controls to detect abnormal activity

Generated by OpenCVE AI on August 4, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Identity Manager Legacy UI

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Identity Manager Legacy UI

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Identity Manager Legacy UI
Weaknesses CWE-306

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Identity Manager Legacy UI
Weaknesses CWE-284
CWE-306

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:58.336Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60330

cve-icon Vulnrichment

Updated: 2026-07-24T13:01:41.952Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses