Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Tue, 04 Aug 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass in Oracle Identity Manager Legacy UI |
Thu, 30 Jul 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass in Oracle Identity Manager Legacy UI |
Tue, 28 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Code Execution in Oracle Identity Manager Legacy UI |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Code Execution in Oracle Identity Manager Legacy UI |
Wed, 22 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
ssvc
|
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle identity Manager |
|
| CPEs | cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle identity Manager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:38:42.354Z
Updated: 2026-08-01T03:56:02.465Z
Reserved: 2026-07-08T15:52:20.740Z
Link: CVE-2026-61196
Updated: 2026-07-22T19:24:03.437Z
Status : Analyzed
Published: 2026-07-21T22:18:51.510
Modified: 2026-08-01T05:17:02.943
Link: CVE-2026-61196
No data.