Oracle Identity Manager vulnerabilities
14 known vulnerabilities affecting oracle/identity_manager.
Total CVEs
14
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH3MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2026-21992CRITICALCVSS 9.8v12.2.1.4.0v14.1.2.1.02026-03-20
CVE-2026-21992 [CRITICAL] CWE-306 CVE-2026-21992: Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST We
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker w
nvd
CVE-2025-61757CRITICALCVSS 9.8KEVPoCv12.2.1.4.0v14.1.2.1.02025-10-21
CVE-2025-61757 [CRITICAL] CWE-306 CVE-2025-61757: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServic
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can resul
nvd
CVE-2021-2458HIGHCVSS 7.6v11.1.2.2.0v11.1.2.3.0+2 more2021-07-21
CVE-2021-2458 [HIGH] CVE-2021-2458: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Identity Conso
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 11.1.2.2.0, 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks require human interact
nvd
CVE-2021-2457MEDIUMCVSS 5.3v11.1.2.3.02021-07-21
CVE-2021-2457 [MEDIUM] CVE-2021-2457: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Request Manage
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Request Management & Workflow). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2020-2728HIGHCVSS 7.5v12.2.1.3.02020-01-15
CVE-2020-2728 [HIGH] CVE-2020-2728: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP use
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP user and role Synch). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2020-2729MEDIUMCVSS 5.4v11.1.2.3.0v12.2.1.3.02020-01-15
CVE-2020-2729 [MEDIUM] CVE-2020-2729: Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Conso
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2019-2858MEDIUMCVSS 4.3v11.1.2.3.0v12.2.1.3.02019-07-23
CVE-2019-2858 [MEDIUM] CVE-2019-2858: Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Ad
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can
nvd
CVE-2019-2729CRITICALCVSS 9.8ExploitedPoCv11.1.2.3.0v12.2.1.3.02019-06-19
CVE-2019-2729 [CRITICAL] CWE-284 CVE-2019-2729: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this
nvd
CVE-2019-11358MEDIUMCVSS 6.1ExploitedPoCv12.2.1.3.02019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2018-3179HIGHCVSS 7.2v11.1.2.3.0v12.2.1.3.02018-10-17
CVE-2018-3179 [HIGH] CVE-2018-3179: Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Ad
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity
nvd
CVE-2017-15095CRITICALCVSS 9.8v11.1.2.3.0v12.2.1.3.02018-02-06
CVE-2017-15095 [CRITICAL] CWE-184 CVE-2017-15095: A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, w
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be us
nvd
CVE-2017-10151CRITICALCVSS 10.0v11.1.1.7v11.1.1.9+4 more2017-10-30
CVE-2017-10151 [CRITICAL] CVE-2017-10151: Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: De
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Orac
nvd
CVE-2017-3553CRITICALCVSS 9.9v11.1.2.3.02017-04-24
CVE-2017-3553 [CRITICAL] CVE-2017-3553: Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Ru
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Rules Engine). The supported version that is affected is 11.1.2.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, att
nvd
CVE-2014-2880MEDIUMCVSS 5.8PoCv11.1.2.1.02014-04-17
CVE-2014-2880 [MEDIUM] CWE-20 CVE-2014-2880: Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.
Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.
nvd