Oracle rushes out emergency patch for Identity Manager

By
Follow google news

Update now to plug 10/10 severity vulnerability.

Oracle has issued an urgent security update for its Identity Manager offering and is urging customers to apply the patch immediately.

Oracle rushes out emergency patch for Identity Manager

While the company did not provide full technical details, it warned that the vulnerability has a "CVSS v3 base score of 10.0, and can result in complete compromise of Oracle Identity Manager via an unauthenticated network attack".

A 10 out 10 CVSS v3 rating indicates the vulnerability is as bad as it gets.

The flaw lies in the Default Account subcomponent of the Oracle Identity Manager.

The US National Institute of Standards said the vulnerability can be easily exploited over the clear text hyper text transmission protocol (HTTP) used for web access.

A successful attack could not only result in full takeover of Oracle's Identity Manager, but also significantly impact additional products, NIST warned.

The emergency patch comes after last month's regular set of security updates, which included 252 fixes for critical flaws in Oracle's products.

Oracle Identity Manager allowes enterprises to manage the user lifecycle across business resources and provides a way to implement corporate policies.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Dead cars tell tales by storing data that's never wiped

Dead cars tell tales by storing data that's never wiped

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Cloud deployment firm Vercel breached, advises secrets rotation

Cloud deployment firm Vercel breached, advises secrets rotation

AI-boosted hacks with Anthropic’s Mythos could have dire consequences for banks

AI-boosted hacks with Anthropic’s Mythos could have dire consequences for banks

Log In

  |  Forgot your password?