logo

Critical 9.8 CVSS Flaw Exposes Oracle Identity Manager to Total Takeover

ID: d754e469-cac9-53a1-9c3f-22d1a71f9d2e

STIX ID: report--d754e469-cac9-53a1-9c3f-22d1a71f9d2e

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-21

Date Updated: 2026-04-23

Author: Ddos

...
...

Oracle has issued an urgent alert for CVE-2026-21992, a critical (CVSS 9.8) vulnerability in Oracle Identity Manager and Oracle Web Services Manager that allows unauthenticated remote attackers via HTTP to take over affected systems (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw resides in REST WebServices and Web Services Security, is described as easily exploitable, and may have broader impact because Oracle Web Services Manager is installed by default with Fusion Middleware Infrastructure; Oracle urges immediate application of updates or mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.