Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspusep2026.html |
|
Sun, 20 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Web Interface Allows Unauthorized Data Manipulation in Oracle Identity Manager |
Sat, 19 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 18 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Exploitation in Oracle Identity Manager Leading to Unauthorized Data Manipulation | |
| Weaknesses | CWE-284 |
Wed, 16 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Exploitation in Oracle Identity Manager Leading to Unauthorized Data Manipulation | |
| Weaknesses | CWE-284 |
Tue, 15 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N). | |
| First Time appeared |
Oracle
Oracle identity Manager |
|
| CPEs | cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle identity Manager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-09-18T18:23:48.602Z
Reserved: 2026-08-31T15:40:57.358Z
Link: CVE-2026-83422
Updated: 2026-09-18T18:15:53.026Z
Status : Analyzed
Published: 2026-09-15T20:18:50.623
Modified: 2026-09-21T18:06:11.027
Link: CVE-2026-83422
No data.
OpenCVE Enrichment
Updated: 2026-09-20T07:45:16Z