Oracle Fusion Middleware Vulnerability Allows Code Execution
Summary
CERT-Bund has issued a security advisory for Oracle Fusion Middleware Identity Manager and Web Services Manager versions prior to 12.2.1.4.0 and 14.1.2.1.0. A critical vulnerability (CVSS 9.8) allows remote attackers to execute arbitrary code, potentially leading to full system compromise.
What changed
CERT-Bund has published a security advisory (WID-SEC-2026-0807) detailing a critical vulnerability in Oracle Fusion Middleware Identity Manager and Web Services Manager. The vulnerability, with a CVSS Base Score of 9.8, allows remote, anonymous attackers to execute arbitrary code on affected systems, potentially leading to complete system compromise. Affected versions include Oracle Fusion Middleware Identity Manager and Web Services Manager prior to 12.2.1.4.0 and 14.1.2.1.0, running on various operating systems including UNIX and Windows.
Organizations utilizing the affected Oracle Fusion Middleware products must urgently apply available mitigations or update to patched versions to prevent exploitation. Failure to address this critical vulnerability could result in severe security breaches, data loss, and system downtime. The advisory indicates that mitigations are available, and users should consult Oracle's security guidance for specific patching and remediation steps.
What to do next
- Apply available mitigations for Oracle Fusion Middleware Identity Manager and Web Services Manager.
- Update affected Oracle Fusion Middleware Identity Manager and Web Services Manager versions to patched releases (12.2.1.4.0 or 14.1.2.1.0 and later).
- Review system logs for any signs of compromise related to this vulnerability.
Source document (simplified)
[WID-SEC-2026-0807] Oracle Fusion Middleware (Identity Manager und Web Services Manager): Schwachstelle ermöglicht Codeausführung CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 19.03.2026 Stand 20.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Sonstiges
- UNIX
- Windows
Produktbeschreibung
Oracle Fusion Middleware bündelt mehrere Produkte zur Erstellung, Betrieb und Management von intelligenten Business Anwendungen.
Produkte
19.03.2026
- Oracle Fusion Middleware Identity Manager <12.2.1.4.0
Oracle Fusion Middleware Web Services Manager <12.2.1.4.0
Oracle Fusion Middleware Identity Manager <14.1.2.1.0
Oracle Fusion Middleware Web Services Manager <14.1.2.1.0
Angriff
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Oracle Fusion Middleware Identity Manager und Web Services Manager ausnutzen, um beliebigen Programmcode auszuführen, was möglicherweise zu einer vollständigen Kompromittierung und Übernahme des Systems führen kann. CVE Informationen Versionshistorie Feedback zum Advisory geben
Named provisions
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.