cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2021-2458,https://securityvulnerability.io/vulnerability/CVE-2021-2458,Authorization Flaw in Oracle Fusion Middleware's Identity Manager,"A significant vulnerability has been identified in the Identity Manager component of Oracle Fusion Middleware. This flaw allows an attacker with low privileges who has network access via HTTP to compromise the Identity Manager system. Exploitation of this vulnerability necessitates human interaction from a user other than the attacker. Although the vulnerability is confined to Identity Manager, it can lead to far-reaching consequences, potentially impacting other associated products. Successful exploitation can grant unauthorized access to sensitive data, enabling attackers to update, insert, or delete crucial information, hence posing a risk of data loss and integrity. Effective security measures are essential to safeguard against such vulnerabilities.",Oracle,Identity Manager,7.6,HIGH,0.0007099999929778278,false,,false,false,false,,,false,false,,2021-07-21T00:15:00.000Z,0 CVE-2021-2457,https://securityvulnerability.io/vulnerability/CVE-2021-2457,Unauthorized Access Vulnerability in Oracle Fusion Middleware Identity Manager,"An unauthorized access vulnerability exists within Oracle Fusion Middleware's Identity Manager component, specifically in Request Management & Workflow. This flaw allows an unauthenticated attacker to exploit the system over HTTP, potentially granting them unauthorized read access to certain sensitive data. The supported version known to be affected is 11.1.2.3.0. Organizations utilizing this software should implement necessary mitigations to prevent unauthorized access and protect their data integrity.",Oracle,Identity Manager,5.3,MEDIUM,0.0009699999936856329,false,,false,false,false,,,false,false,,2021-07-21T00:15:00.000Z,0 CVE-2020-14874,https://securityvulnerability.io/vulnerability/CVE-2020-14874,Vulnerability in Oracle Cloud Infrastructure Identity and Access Management,"A vulnerability exists within Oracle Cloud Infrastructure Identity and Access Management that can be exploited by a high privileged attacker with network access. This flaw allows for unauthorized updates, insertions, or deletions of accessible data. Additionally, it can lead to unauthorized read access to certain data and the ability to partially disrupt services, resulting in a significant risk to cloud service integrity and availability.",Oracle,Oracle Cloud Infrastructure Identity And Access Management,4.7,MEDIUM,0.000910000002477318,false,,false,false,false,,,false,false,,2020-12-22T21:40:14.000Z,0 CVE-2020-2728,https://securityvulnerability.io/vulnerability/CVE-2020-2728,Unauthenticated Access Vulnerability in Oracle Fusion Middleware Identity Manager,"A vulnerability exists in the Identity Manager component of Oracle Fusion Middleware, specifically affecting the LDAP user and role synchronization feature. This flaw allows an unauthenticated attacker with network access via HTTP to exploit the system, potentially leading to unauthorized access to sensitive information. Successful exploitation can compromise the integrity of Identity Manager and expose critical data, emphasizing the importance of immediate mitigation measures.",Oracle,Identity Manager,7.5,HIGH,0.0036100000143051147,false,,false,false,false,,,false,false,,2020-01-15T16:34:09.000Z,0 CVE-2020-2729,https://securityvulnerability.io/vulnerability/CVE-2020-2729,Vulnerability in Identity Manager of Oracle Fusion Middleware,"A vulnerability exists in the Identity Manager component of Oracle Fusion Middleware that allows low-privileged attackers with network access via HTTP to compromise the system. This exploitation leads to potential unauthorized modifications, insertions, or deletions of accessible data, as well as unapproved reading of certain data sets. Users should upgrade to the latest versions to mitigate this risk and secure their environments.",Oracle,Identity Manager,5.4,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2020-01-15T16:34:09.000Z,0 CVE-2019-2858,https://securityvulnerability.io/vulnerability/CVE-2019-2858,Vulnerability in Oracle Identity Manager Component of Oracle Fusion Middleware,"The vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware, specifically the Advanced Console subcomponent, allows low-privileged attackers with network access to exploit the system via HTTP. This exploitation can lead to unauthorized updates, inserts, or deletions of data accessible by Oracle Identity Manager. Supported versions affected include 11.1.2.3.0 and 12.2.1.3.0. Security measures should be taken to mitigate the risk of unauthorized data manipulation.",Oracle,Identity Manager,4.3,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2019-07-23T23:15:00.000Z,0 CVE-2018-3179,https://securityvulnerability.io/vulnerability/CVE-2018-3179,,"Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Identity Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Identity Manager. CVSS 3.0 Base Score 7.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L).",Oracle,Identity Manager,7.2,HIGH,0.0006500000017695129,false,,false,false,false,,,false,false,,2018-10-17T01:00:00.000Z,0 CVE-2017-10151,https://securityvulnerability.io/vulnerability/CVE-2017-10151,,"Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",Oracle,Identity Manager,10,CRITICAL,0.003100000089034438,false,,false,false,false,,,false,false,,2017-10-30T20:00:00.000Z,0 CVE-2017-10270,https://securityvulnerability.io/vulnerability/CVE-2017-10270,,"Vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware (subcomponent: Microsoft Active Directory). The supported version that is affected is 9.1.1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.0 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H).",Oracle,Identity Manager Connector,8.2,HIGH,0.0007699999841861427,false,,false,false,false,,,false,false,,2017-10-19T17:00:00.000Z,0 CVE-2017-3553,https://securityvulnerability.io/vulnerability/CVE-2017-3553,,"Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Rules Engine). The supported version that is affected is 11.1.2.3.0. Easily ""exploitable"" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",Oracle,Identity Manager,9.9,CRITICAL,0.001970000099390745,false,,false,false,false,,,false,false,,2017-04-24T19:00:00.000Z,0 CVE-2016-5506,https://securityvulnerability.io/vulnerability/CVE-2016-5506,,Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware allows local users to affect confidentiality and integrity via vectors related to App Server.,Oracle,Identity Manager,3.1,LOW,0.000539999979082495,false,,false,false,false,,,false,false,,2016-10-25T14:00:00.000Z,0 CVE-2014-2880,https://securityvulnerability.io/vulnerability/CVE-2014-2880,,"Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.",Oracle,Identity Manager,,,0.024450000375509262,false,,false,false,false,,,false,false,,2014-04-17T14:00:00.000Z,0 CVE-2014-2411,https://securityvulnerability.io/vulnerability/CVE-2014-2411,,"Unspecified vulnerability in the Oracle Identity Analytics component in Oracle Fusion Middleware Oracle Identity Analytics 11.1.1.5 and Sun Role Manager 5.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Security.",Oracle,"Sun Role Manager,Identity Analytics",,,0.08728999644517899,false,,false,false,false,,,false,false,,2014-04-16T02:05:00.000Z,0 CVE-2013-5815,https://securityvulnerability.io/vulnerability/CVE-2013-5815,,"Unspecified vulnerability in the Oracle Identity Analytics component in Oracle Fusion Middleware Oracle Identity Analytics 11.1.1.5 and Sun Role Manager 4.1 and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.",Oracle,"Sun Role Manager,Identity Analytics",,,0.010649999603629112,false,,false,false,false,,,false,false,,2013-10-16T17:55:00.000Z,0 CVE-2009-1075,https://securityvulnerability.io/vulnerability/CVE-2009-1075,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.",Oracle,Java System Identity Manager,,,0.036720000207424164,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1083,https://securityvulnerability.io/vulnerability/CVE-2009-1083,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits ""control characters"" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving ""resource adapters.""",Oracle,Java System Identity Manager,,,0.004519999958574772,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1074,https://securityvulnerability.io/vulnerability/CVE-2009-1074,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to ""ssl termination devices"" and lack of support for relative URLs.",Oracle,Java System Identity Manager,,,0.005969999823719263,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1076,https://securityvulnerability.io/vulnerability/CVE-2009-1076,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.",Oracle,Java System Identity Manager,,,0.009920000098645687,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1077,https://securityvulnerability.io/vulnerability/CVE-2009-1077,,"The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password.",Oracle,Java System Identity Manager,,,0.010339999571442604,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1078,https://securityvulnerability.io/vulnerability/CVE-2009-1078,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.",Oracle,Java System Identity Manager,,,0.00610999995842576,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1082,https://securityvulnerability.io/vulnerability/CVE-2009-1082,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs.",Oracle,Java System Identity Manager,,,0.0038300000596791506,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1081,https://securityvulnerability.io/vulnerability/CVE-2009-1081,,"Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.",Oracle,Java System Identity Manager,,,0.004889999981969595,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1080,https://securityvulnerability.io/vulnerability/CVE-2009-1080,,"Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.",Oracle,Java System Identity Manager,,,0.004889999981969595,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1079,https://securityvulnerability.io/vulnerability/CVE-2009-1079,,"Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683.",Oracle,Java System Identity Manager,,,0.004889999981969595,false,,false,false,false,,,false,false,,2009-03-25T15:30:00.000Z,0 CVE-2009-1084,https://securityvulnerability.io/vulnerability/CVE-2009-1084,,"Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.",Oracle,Java System Identity Manager,,,0.00203000009059906,false,,false,false,false,,,false,false,,2009-03-25T15:00:00.000Z,0