CVE-2026-83422
moderateUnauthenticated Data Tampering in Oracle Identity Manager Legacy UI
Oracle Identity Manager (OIM), part of Oracle Fusion Middleware, contains a flaw in its Legacy UI component affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable by an unauthenticated attacker with HTTP network access, but successful attacks require interaction from a person other than the attacker, consistent with a CSRF/session-riding style attack against an OIM user. A successful exploit yields unauthorized creation, deletion, or modification of critical data and unauthorized read access to some or all OIM-accessible data, with high confidentiality and integrity impact (CVSS 3.1 base score 8.1, no availability impact). Organizations running the affected OIM versions with the Legacy UI reachable over the network are at risk. No public proof of concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE to all OIM 12.2.1.4.0 and 14.1.2.1.0 installations. If the Legacy UI is not required, disable or remove it, and restrict HTTP access to OIM consoles via VPN or IP allowlisting. Review OIM audit logs for anomalous unauthenticated requests or unexpected changes to identity, role, and provisioning data.
| Oracle Identity Manager (Oracle Fusion Middleware, OIM Legacy UI component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.