ZeroHour

CVE-2026-73943

moderate

Privileged Data-Access Flaw in Oracle Identity Manager Legacy UI

CVSS 3.1
7.6 high
EPSS
Published
()
Modified
AI analysis

Oracle Identity Manager (OIM) versions 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware, contain an easily exploitable vulnerability in the OIM Legacy UI component. A high-privileged attacker with network access via HTTP — with no user interaction and low attack complexity — can compromise Oracle Identity Manager. Due to a scope change, successful attacks may significantly impact additional products beyond OIM itself, resulting in unauthorized access to critical data or complete access to all OIM-accessible data, plus unauthorized update, insert, or delete access to some of that data. Organizations running the affected OIM versions, particularly those with the Legacy UI reachable over the network by privileged users, are at risk. The CVE is not on CISA's KEV list and no public proof of concept is known, so exploitation in the wild is not currently evident.

What to do: Apply Oracle's Critical Patch Update fixes for Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 as soon as they are available. Until patched, restrict network access to the OIM Legacy UI (VPN/IP allowlisting), disable the Legacy UI if it is not required, and prefer the modern UI. Audit high-privileged OIM accounts for misuse and monitor for anomalous bulk reads or unauthorized data modifications across connected applications.

Affected
Oracle Fusion Middleware / Oracle Identity Manager (OIM Legacy UI)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
moderatelikely a few thousand internet-reachable OIM Legacy UI endpoints, with total enterprise deployments in the low tens of thousands — OIM is an enterprise-only identity governance product; public scans show tens of thousands of internet-exposed Oracle Fusion Middleware hosts of which OIM is a small subset, and many OIM deployments are internal-only.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.