← Back to Products

identity_manager

Vendor: oracle

2
Total CVEs
2
Critical
0
High
0
Medium
0
Low

Recent CVEs

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Servi...

Affected versions: 12.2.1.4.0 14.1.2.1.0

Published: Mar 20, 2026

9.8

CVSS

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulner...

Affected versions: 12.2.1.4.0 14.1.2.1.0

Published: Oct 21, 2025

9.8

CVSS

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerab...

Affected versions: 11.1.2.3.0 12.2.1.3.0

Published: Jan 15, 2020

5.4

CVSS

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP user and role Synch). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerab...

Affected versions: 12.2.1.3.0

Published: Jan 15, 2020

7.5

CVSS

Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploita...

Affected versions: 11.1.2.3.0 12.2.1.3.0

Published: Jul 23, 2019

4.0

CVSS

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily e...

Affected versions: 11.1.2.3.0 12.2.1.3.0

Published: Jun 19, 2019

9.8

CVSS

The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability....

Affected versions: 2.7.7.7 4.0.1 4.0.2 4.0.2.0 4.5 +4 more

Published: May 9, 2019

5.0

CVSS

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an en...

Affected versions: 12.2.1.3.0

Published: Apr 20, 2019

6.1

CVSS

Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploita...

Affected versions: 11.1.2.3.0 12.2.1.3.0

Published: Oct 17, 2018

6.4

CVSS

The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information....

Affected versions: 4.0.2 4.5 4.6

Published: Mar 28, 2018

4.3

CVSS

The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection....

Affected versions: 4.0.2 4.5 4.6

Published: Mar 28, 2018

5.8

CVSS

The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack....

Affected versions: 4.0.2 4.5 4.6

Published: Mar 26, 2018

5.0

CVSS

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration....

Affected versions: 4.0.2 4.5 4.6

Published: Mar 26, 2018

5.0

CVSS

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration....

Affected versions: 4.0.2 4.5 4.6

Published: Mar 26, 2018

5.0

CVSS

NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack....

Affected versions: 4.0.2 4.5 4.6

Published: Mar 26, 2018

5.8

CVSS

Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary J...

Affected versions: 4.0.2 4.5 4.6

Published: Mar 5, 2018

4.3

CVSS

Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, ...

Affected versions: 4.0.2 4.5

Published: Mar 2, 2018

5.0

CVSS

NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user adminis...

Affected versions: 4.0.2 4.5

Published: Mar 2, 2018

9.0

CVSS

In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles....

Affected versions: 4.0.2 4.5

Published: Mar 2, 2018

5.0

CVSS

The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks....

Affected versions: 4.0.2 4.5 4.6

Published: Mar 1, 2018

6.4

CVSS

Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2...

Affected versions: 2016

Published: Feb 26, 2018

4.3

CVSS

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafte...

Affected versions: 11.1.2.3.0 12.2.1.3.0

Published: Feb 6, 2018

9.8

CVSS

Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exp...

Affected versions: 11.1.1.7 11.1.1.9 11.1.2.1.0 11.1.2.2.0 11.1.2.3 +1 more

Published: Oct 30, 2017

7.5

CVSS

CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search....

Affected versions: 12.6 14.0 14.1

Published: Sep 22, 2017

5.0

CVSS

Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Rules Engine). The supported version that is affected is 11.1.2.3.0. Easily "exploitable" vulnerabilit...

Affected versions: 11.1.2.3.0

Published: Apr 24, 2017

7.5

CVSS

XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages....

Affected versions: 4.5

Published: Oct 27, 2016

3.5

CVSS

XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI....

Affected versions: 4.0.2 4.5

Published: Oct 27, 2016

4.3

CVSS

XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI....

Affected versions: 4.0.2 4.5

Published: Oct 27, 2016

4.3

CVSS

Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware allows local users to affect confidentiality and integrity via vectors related to App Server....

Affected versions: -

Published: Oct 25, 2016

3.3

CVSS

The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirector...

Affected versions: 4.0.2

Published: Jun 21, 2014

4.6

CVSS

Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web s...

Affected versions: 11.1.2.1.0

Published: Apr 17, 2014

5.8

CVSS

The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by reading this file....

Affected versions: 3.6.1

Published: Sep 8, 2010

2.1

CVSS

The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and ...

Affected versions: 3.0.1

Published: Sep 14, 2006

7.2

CVSS

idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backslash) characters and ev...

Affected versions: 3.0.1

Published: Aug 31, 2006

3.6

CVSS