Description
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data manipulation and confidentiality breach
Action: Patch immediately
AI Analysis

Impact

The vulnerability resides in Oracle Identity Manager’s legacy UI and permits an unauthenticated attacker accessing the web interface over HTTP to create, modify, or delete data that the Identity Manager manages. The flaw requires human interaction from a third party to complete the exploit but does not grant full system compromise or code execution. The impact is a loss of confidentiality and integrity for critical data, as an attacker can alter or delete records stored in Oracle Identity Manager.

Affected Systems

Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 are affected.

Risk and Exploitability

The CVSS 3.1 base score is 8.1, with an access vector of network and no privileges required, user interaction required, and a high impact on confidentiality and integrity. The EPSS score is less than 1 %, indicating a low probability of exploitation at the time of analysis. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker can exploit the flaw by sending crafted requests to the web service from any system that can reach the Identity Manager’s HTTP port, but the presence of a human interaction step reduces the likelihood of automated attacks.

Generated by OpenCVE AI on September 20, 2026 at 07:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle security patch or upgrade to a version that contains the fix for OIM 12.2.1.4.0 and 14.1.2.1.0.
  • Limit network exposure by restricting HTTP traffic to the Oracle Identity Manager instance to only trusted internal networks or VPN endpoints.
  • Enable logging and actively monitor web access logs for anomalous requests that could indicate exploitation attempts.
  • Consider tightening authentication mechanisms for the Legacy UI if possible to add an additional layer of protection.

Generated by OpenCVE AI on September 20, 2026 at 07:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Web Interface Allows Unauthorized Data Manipulation in Oracle Identity Manager

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in Oracle Identity Manager Leading to Unauthorized Data Manipulation
Weaknesses CWE-284

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploitation in Oracle Identity Manager Leading to Unauthorized Data Manipulation
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle identity Manager
CPEs cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Identity Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:48.602Z

Reserved: 2026-08-31T15:40:57.358Z

Link: CVE-2026-83422

cve-icon Vulnrichment

Updated: 2026-09-18T18:15:53.026Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:50.623

Modified: 2026-09-21T18:06:11.027

Link: CVE-2026-83422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:45:16Z

Weaknesses