Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Identity Manager contains a REST WebServices vulnerability that allows a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data, as well as gain unauthorized read access to all data managed by the application. The flaw results in severe confidentiality and integrity impacts and is assessed with a CVSS 3.1 base score of 8.1, indicating high severity.

Affected Systems

Affected products are Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0.

Risk and Exploitability

The vulnerability can be exploited from any network location that can reach the OIM REST endpoint; a low‑privileged user does not need elevated credentials. Although the EPSS score is below 1 % and the flaw is not currently listed in the CISA KEV catalog, the high CVSS score and direct network attack surface mean that an adversary could persistently abuse the flaw if unpatched. The primary attack vector is via crafted HTTP requests to the vulnerable REST services.

Generated by OpenCVE AI on August 4, 2026 at 03:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Oracle Identity Manager 12.2.1.4.0 or 14.1.2.1.0 as detailed in the Oracle CPU for July 2026
  • Limit HTTP access to the OIM REST services to trusted networks or enforce VPN or firewall rules to restrict who can reach the endpoint
  • Configure Oracle Identity Manager to enforce strict authentication and authorization checks on all API endpoints, ensuring that only privileged users can perform create, delete, or modify operations

Generated by OpenCVE AI on August 4, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthorized data manipulation via REST services in Oracle Identity Manager

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthorized data manipulation via REST services in Oracle Identity Manager

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote REST WebServices Vulnerability Allowing Unauthorized Data Modification in Oracle Identity Manager

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Remote REST WebServices Vulnerability Allowing Unauthorized Data Modification in Oracle Identity Manager
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:55:59.435Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60560

cve-icon Vulnrichment

Updated: 2026-07-27T11:50:52.236Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses