ZeroHour

CVE-2026-70913

moderate

Unauthenticated HTTP Takeover Flaw in Oracle Identity Manager (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

A critical vulnerability (CVSS 3.1 base score 9.8) in the Core component of Oracle Identity Manager, part of Oracle Fusion Middleware, allows an unauthenticated attacker with network access via HTTP to completely compromise the product. The flaw is rated easily exploitable, with no privileges required, no user interaction, and low attack complexity, meaning any network-reachable OIM HTTP endpoint is a viable target. A successful attack results in full takeover of Oracle Identity Manager, with high impact on the confidentiality, integrity, and availability of the identity management services it fronts. Supported versions 12.2.1.4.0 and 14.1.2.1.0 are affected. No public proof-of-concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 installations as soon as it is available; since no fixed version is listed here, confirm the patch target in Oracle's advisory. Until patched, restrict HTTP access to OIM and its managed-server ports via firewall allow-lists or VPN and eliminate any internet exposure of the console. Review OIM logs and configuration for unauthorized accounts, altered provisioning workflows, or anomalous credential access if the system was reachable.

Affected
Oracle Identity Manager (Oracle Fusion Middleware, component: Core)
Estimated exposure
moderateon the order of a few thousand enterprise OIM deployments worldwide, with a smaller internet-exposed subset — Oracle Identity Manager is a licensed enterprise IAM product with no public install counts; deployment patterns and public scan engines historically show low-thousands of internet-reachable Oracle Fusion Middleware/OIM consoles, so this is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.