Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Identity Manager (OIM) is vulnerable due to a flaw in the legacy user interface component. A low‑privileged attacker with network access to the T3 or IIOP protocols can compromise the system. Successful exploitation would allow an attacker to take complete control of OIM, resulting in full loss of confidentiality, integrity, and availability. The vulnerability is assessed with a CVSS 3.1 base score of 8.8, reflecting high impact and low attack complexity.

Affected Systems

Affected versions are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0. These releases are part of the Oracle Fusion Middleware suite and are deployed in many enterprise environments that manage identity, governance, and privileged access. Only the legacy UI component of OIM is impacted; other modules are not mentioned.

Risk and Exploitability

The risk is high because the flaw can be exploited over the network with only local privileges and no user interaction. The EPSS score is not available, but the CVSS score and absence of remediation listed in KEV indicate that it has not yet been widely attacked in the wild. Attackers would likely use the exposed T3/IIOP interfaces to send crafted requests that bypass authorization checks, taking advantage of the CWE‑284 and CWE‑732 weaknesses. Until a patch is applied, the vulnerability remains exploitable.

Generated by OpenCVE AI on August 18, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle Identity Manager patch that fixes CVE‑2026‑60722, as released in the Oracle security alert.
  • Block or tightly restrict T3 and IIOP traffic to the OIM servers from untrusted networks to reduce attack surface.
  • Enforce network segmentation so that only trusted administrative hosts can reach the OIM instance, and regularly audit the system for unexpected privileged accounts.

Generated by OpenCVE AI on August 18, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Oracle Identity Manager Low‑Privilege Remote Takeover via T3/IIOP
Weaknesses CWE-284
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:01.415Z

Reserved: 2026-07-08T15:51:55.583Z

Link: CVE-2026-60722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:40.380

Modified: 2026-08-18T21:16:40.380

Link: CVE-2026-60722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-732

    Incorrect Permission Assignment for Critical Resource