Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Legacy UI component of Oracle Identity Manager. An attacker who only has standard network connectivity to the OIM server can send HTTP requests without authentication, enabling the creation, deletion or alteration of critical data and granting full read access to all data handled by the system. This results in significant confidentiality and integrity impacts, as the attacker can manipulate or exfiltrate sensitive information.

Affected Systems

Affected are Oracle Identity Manager releases 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware. Systems running these versions are at risk if the Legacy UI component remains exposed and accessible.

Risk and Exploitability

The CVSS score of 9.1 reflects severe confidentiality and integrity impact with no need for authentication. The EPSS score is below 1%, indicating low observed exploitation frequency to date, and the vulnerability is not yet listed in CISA’s KEV catalog. Nevertheless, the remote attack path via publicly reachable HTTP and the complete lack of authentication make it highly actionable; organizations with exposed OIM interfaces should prioritize remediation.

Generated by OpenCVE AI on August 2, 2026 at 21:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the CPUJul2026 security advisory to update Oracle Identity Manager to a fixed version.
  • If a patch cannot be applied immediately, disable or remove the Legacy UI component or block HTTP access to the OIM server from untrusted networks.
  • Restrict network access to the OIM server by enforcing firewall rules that allow connections only from trusted IP ranges and enable authentication mechanisms such as LDAP or Kerberos for all endpoints.

Generated by OpenCVE AI on August 2, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Disclosure in Oracle Identity Manager

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Identity Manager
Weaknesses CWE-284

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Identity Manager
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:00.795Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60567

cve-icon Vulnrichment

Updated: 2026-07-27T14:29:21.308Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management