Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker with low privileges who can reach the Oracle Identity Manager web interface over HTTP can exploit a vulnerability in the legacy UI component to take complete control of the OIM instance. The flaw allows the attacker to compromise confidentiality, integrity, and availability of all managed identities and potentially other downstream applications, as the vulnerability carries a scope change. The CVSS 3.1 base score of 9.9 and the vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) indicate a highly severe risk that is readily exploitable over a network connection with minimal effort.

Affected Systems

The affected products are Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 from Oracle Corporation. No other product versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 9.9 places this issue in the critical severity range. While the EPSS score is not available, the lack of an available exploitation rate does not diminish the classified attack path, involving HTTP access to the Legacy UI. The vulnerability is not listed in the CISA KEV catalog, but the high severity score and scope change endorse a rapid response to mitigate potential compromise. An attacker with simple network access can exercise the vulnerability without authentication or user interaction, suggesting the potential for automated exploitation if a host is exposed.

Generated by OpenCVE AI on August 18, 2026 at 23:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Oracle support to obtain the latest security patch for Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 and apply it immediately.
  • Restrict network connectivity to the OIM web interface by configuring firewall rules or VPN access so that only trusted IP addresses can reach the affected ports.
  • Enable additional authentication controls such as multi‑factor authentication or tighter session management on the OIM application to reduce the impact of a low‑privileged attacker.

Generated by OpenCVE AI on August 18, 2026 at 23:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attacker Can Compromise Oracle Identity Manager
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:00.786Z

Reserved: 2026-07-08T15:51:55.582Z

Link: CVE-2026-60720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:40.140

Modified: 2026-08-18T21:16:40.140

Link: CVE-2026-60720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses