Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

Oracle Identity Manager’s Legacy UI component contains an authentication and access‑control flaw that can be exploited by an attacker with low privileges and network access over HTTP. of the Oracle Identity Manager instance, resulting in complete loss of confidentiality, integrity, and availability for that system. The vulnerability is classified as CWE‑284, indicating a weakness in controlling access to resources.

Affected Systems

The product is Oracle Identity Manager. The vulnerability impacts version 12.2.1.4.0 and version 14.1.2.1.0.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 reflects a high‑severity flaw with complete impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a very low current probability of exploitation, but the flaw is not present in the CISA KEV catalog. Based on the description, the likely attack vector is a remote HTTP request from a low‑privileged attacker that takes advantage of missing or weak authentication controls to gain full control of the system.

Generated by OpenCVE AI on September 17, 2026 at 06:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict HTTP access to the Oracle Identity Manager instance by configuring firewalls or access control lists so that only trusted networks can reach the OIM services, reducing the exposure surface for potential attackers.
  • Enable comprehensive logging of authentication attempts and privileged actions against OIM, and actively monitor logs for anomalous activity promptly.
  • Stay informed on Oracle security advisories and apply any official updates that address the vulnerability when they become available.

Generated by OpenCVE AI on September 17, 2026 at 06:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:30:25.715Z

Reserved: 2026-08-13T18:41:45.892Z

Link: CVE-2026-73942

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:56.482Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:45.160

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-73942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T07:00:24Z

Weaknesses