ZeroHour

CVE-2026-83422

moderate

Unauthenticated Data Tampering in Oracle Identity Manager Legacy UI

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

Oracle Identity Manager (OIM), part of Oracle Fusion Middleware, contains a flaw in its Legacy UI component affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable by an unauthenticated attacker with HTTP network access, but successful attacks require interaction from a person other than the attacker, consistent with a CSRF/session-riding style attack against an OIM user. A successful exploit yields unauthorized creation, deletion, or modification of critical data and unauthorized read access to some or all OIM-accessible data, with high confidentiality and integrity impact (CVSS 3.1 base score 8.1, no availability impact). Organizations running the affected OIM versions with the Legacy UI reachable over the network are at risk. No public proof of concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all OIM 12.2.1.4.0 and 14.1.2.1.0 installations. If the Legacy UI is not required, disable or remove it, and restrict HTTP access to OIM consoles via VPN or IP allowlisting. Review OIM audit logs for anomalous unauthenticated requests or unexpected changes to identity, role, and provisioning data.

Affected
Oracle Identity Manager (Oracle Fusion Middleware, OIM Legacy UI component)
Estimated exposure
moderatethousands of enterprise OIM deployments (order of 1k-10k systems), with only a small fraction internet-exposed — OIM is licensed enterprise identity-management middleware typically deployed at thousands of organizations and hosted on internal networks, so the externally reachable subset is small (deployment-pattern estimate, clearly approximate).

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.