Changeflow GovPing Data Privacy & Cybersecurity Oracle Fusion Middleware Vulnerability Allows C...
Urgent Notice Added Final

Oracle Fusion Middleware Vulnerability Allows Code Execution

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 19th, 2026
Detected March 20th, 2026
Email

Summary

CERT-Bund has issued a security advisory for Oracle Fusion Middleware Identity Manager and Web Services Manager versions prior to 12.2.1.4.0 and 14.1.2.1.0. A critical vulnerability (CVSS 9.8) allows remote attackers to execute arbitrary code, potentially leading to full system compromise.

What changed

CERT-Bund has published a security advisory (WID-SEC-2026-0807) detailing a critical vulnerability in Oracle Fusion Middleware Identity Manager and Web Services Manager. The vulnerability, with a CVSS Base Score of 9.8, allows remote, anonymous attackers to execute arbitrary code on affected systems, potentially leading to complete system compromise. Affected versions include Oracle Fusion Middleware Identity Manager and Web Services Manager prior to 12.2.1.4.0 and 14.1.2.1.0, running on various operating systems including UNIX and Windows.

Organizations utilizing the affected Oracle Fusion Middleware products must urgently apply available mitigations or update to patched versions to prevent exploitation. Failure to address this critical vulnerability could result in severe security breaches, data loss, and system downtime. The advisory indicates that mitigations are available, and users should consult Oracle's security guidance for specific patching and remediation steps.

What to do next

  1. Apply available mitigations for Oracle Fusion Middleware Identity Manager and Web Services Manager.
  2. Update affected Oracle Fusion Middleware Identity Manager and Web Services Manager versions to patched releases (12.2.1.4.0 or 14.1.2.1.0 and later).
  3. Review system logs for any signs of compromise related to this vulnerability.

Source document (simplified)

[WID-SEC-2026-0807] Oracle Fusion Middleware (Identity Manager und Web Services Manager): Schwachstelle ermöglicht Codeausführung CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 19.03.2026 Stand 20.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Sonstiges
  • UNIX
  • Windows

Produktbeschreibung

Oracle Fusion Middleware bündelt mehrere Produkte zur Erstellung, Betrieb und Management von intelligenten Business Anwendungen.

Produkte

19.03.2026
- Oracle Fusion Middleware Identity Manager <12.2.1.4.0

  • Oracle Fusion Middleware Web Services Manager <12.2.1.4.0

  • Oracle Fusion Middleware Identity Manager <14.1.2.1.0

  • Oracle Fusion Middleware Web Services Manager <14.1.2.1.0

Angriff

Angriff

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Oracle Fusion Middleware Identity Manager und Web Services Manager ausnutzen, um beliebigen Programmcode auszuführen, was möglicherweise zu einer vollständigen Kompromittierung und Übernahme des Systems führen kann. CVE Informationen Versionshistorie Feedback zum Advisory geben

Named provisions

Betroffene Systeme Angriff

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 19th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-0807

Who this affects

Applies to
Technology companies
Industry sector
3341 Computer & Electronics Manufacturing 5112 Software & Technology 5182 Data Processing & Hosting
Activity scope
Software Vulnerability Management System Security
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Software Vulnerabilities Information Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.