Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Identity Manager Legacy UI allows an attacker with modest privileges to use the HTTP interface to fully compromise the management service. The vulnerability is easily exploitable from remote networks and leads to a total loss of confidentiality, integrity, and availability: an attacker can read, modify, and delete all identity data and commands, effectively seizing control of the system. The weakness grants elevated rights without requiring authentication or privilege escalation, creating a path for full takeover.

Affected Systems

Affected versions are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware. Environment is accessed via standard HTTP endpoints; the flaw exists in the legacy user interface component.

Risk and Exploitability

The CVSS score of 8.8 signals a high severity. The attack vector is straightforward: an external attacker can reach the HTTP service over the network. Because no exploitation probability (EPSS) is available and the vulnerability is not listed in CISA's KEV, the exploit risk is unquantified but likely significant for exposed deployments. As the flaw allows complete takeover, the impact for affected sites is critical, especially for enterprises relying on identity management for privileged operations.

Generated by OpenCVE AI on August 18, 2026 at 23:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Identity Manager security patch released by Oracle for versions 12.2.1.4.0 and 14.1.2.1.0
  • Restrict HTTP access to the OIM Legacy UI to trusted internal networks or enforce VPN/SSO constraints
  • Implement strict authentication and session validation on the OIM web interface, ensuring that only fully authenticated users can access management functions

Generated by OpenCVE AI on August 18, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Identity Manager Leads to Remote Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:00.149Z

Reserved: 2026-07-08T15:51:55.581Z

Link: CVE-2026-60715

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:39.897

Modified: 2026-08-18T21:16:39.897

Link: CVE-2026-60715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses