Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Identity Manager (OIM) is vulnerable due to a flaw in the legacy user interface component. A low‑privileged attacker with network access to the T3 or IIOP protocols can compromise the system. Successful exploitation would allow an attacker to take complete control of OIM, resulting in full loss of confidentiality, integrity, and availability. The vulnerability is assessed with a CVSS 3.1 base score of 8.8, reflecting high impact and low attack complexity.

Affected Systems

Affected versions are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0. These releases are part of the Oracle Fusion Middleware suite and are deployed in many enterprise environments that manage identity, governance, and privileged access. Only the legacy UI component of OIM is impacted; other modules are not mentioned.

Risk and Exploitability

The risk is high because the flaw can be exploited over the network with only local privileges and no user interaction. The EPSS score of 0.00432 (<1%) indicates a low probability of exploitation, and the absence of a KEV listing suggests it has not yet been widely attacked. Attackers would likely use the exposed T3/IIOP interfaces to send crafted requests that bypass authorization checks, taking advantage of the CWE‑306 weakness. Until a patch is applied, the vulnerability remains exploitable.

Generated by OpenCVE AI on August 21, 2026 at 17:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle Identity Manager patch that fixes CVE‑2026‑60722, as released in the Oracle security alert.
  • Block or tightly restrict T3 and IIOP traffic to the OIM servers from untrusted networks to reduce attack surface.
  • Enforce network segmentation so that only trusted administrative hosts can reach the OIM instance, and regularly audit the system for unexpected privileged accounts.

Generated by OpenCVE AI on August 21, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Low‑privileged Network Attack Allows Full Takeover of Oracle Identity Manager

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Oracle Identity Manager Low‑Privilege Remote Takeover via T3/IIOP
Weaknesses CWE-284
CWE-732

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Oracle Identity Manager Low‑Privilege Remote Takeover via T3/IIOP
Weaknesses CWE-284
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:49:38.044Z

Reserved: 2026-07-08T15:51:55.583Z

Link: CVE-2026-60722

cve-icon Vulnrichment

Updated: 2026-08-20T17:48:34.886Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:40.380

Modified: 2026-08-20T18:16:33.463

Link: CVE-2026-60722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses