Sceawere

Vulnerability Detail

CVE-2026-61197Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Identity Manager Unauthorized Access

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Identity Manager
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-07-21T22:18:51.620Z",
  "pubdate": "2026-07-21T22:18:51.620Z",
  "executiveSummary": "This vulnerability concerns a high-severity security flaw within the Oracle Identity Manager (OIM) Legacy UI component of Oracle Fusion Middleware. It is classified as an authorization bypass or insecure direct object reference issue that allows an unauthenticated remote attacker to gain unauthorized access to the system.\nThe vulnerability carries a CVSS 3.1 base score of 9.1, reflecting its significant impact on data confidentiality and integrity. Successful exploitation grants an attacker the ability to perform unauthorized create, read, update, and delete (CRUD) operations on critical identity data stored within the OIM environment.\nBecause the vulnerability requires no authentication and can be exploited over HTTP, it poses a severe risk to organizational identity governance. An attacker can leverage this flaw to manipulate user identities, escalate privileges, or extract sensitive information, effectively compromising the integrity of the entire identity management infrastructure.\nAffected software versions include Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0. Given the ease of exploitation, organizations running these versions are at immediate risk of data exfiltration and unauthorized management of enterprise identity assets.",
  "technicalDetails": "The vulnerability resides within the OIM Legacy UI component of Oracle Fusion Middleware. It stems from improper access control enforcement on sensitive backend functions, allowing unauthorized users to interface with critical data-handling logic without undergoing necessary authentication or authorization protocols.\nThe vulnerability is characterized by a CVSS vector of (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). The 'AV:N' (Network) and 'AC:L' (Low Complexity) indicators confirm that an attacker only requires standard network connectivity to the target service to initiate an attack. The absence of required privileges ('PR:N') and user interaction ('UI:N') makes this a highly critical 'zero-click' entry point for malicious actors.\nThe attack flow begins when an attacker directs specially crafted HTTP requests to the exposed OIM Legacy UI endpoints. Because the component fails to validate the session state or authorization context before executing requested operations, the application processes these requests as if they were originated by an authenticated administrative user.\nWhen an attacker sends a malicious payload to the OIM Legacy UI, the application executes the intended business logic without verifying if the caller possesses the necessary permissions. This allows the attacker to interact with the underlying Oracle Identity Manager database directly through the UI's API surface.\nPost-exploitation impact includes the full manipulation of identity records. Attackers can create new identities with elevated privileges, modify existing user attributes to facilitate lateral movement within the network, or delete critical configuration data, resulting in loss of data integrity and potential operational disruption. Confidentiality is also severely impacted, as the attacker can read, dump, or exfiltrate all identity information accessible to the OIM system, including sensitive credentials or administrative metadata.\nThe vulnerability is specific to versions 12.2.1.4.0 and 14.1.2.1.0. Given the design of the Legacy UI component, the lack of input/request validation creates an environment where internal data management functions are exposed to the public-facing or internal-facing network without adequate security boundaries."
}
CVE-2026-61197: Oracle Identity Manager Unauthorized Access (CRITICAL Severity, CVSS: 9.1) - Sceawere