Vulnerabilità ed exploit · Attacco ad app web

Oracle rilascia patch d'emergenza per RCE pre-auth in Identity Manager

La vulnerabilità ha CVSS 9.8 e permette a un attaccante non autenticato via HTTP(S) di eseguire codice remoto senza interazione utente. Le versioni 12.2.1.4.0 e 14.1.2.1.0 sono confermate vulnerabili; release non supportate potrebbero esserlo.

6 fonti · 23 mar

CVE-2026-21992

NVD KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and… EPSS 1% (58º percentile), in aumento rispetto a 0.07%.

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-24

Every edition of this story: Oracle rilascia patch d'emergenza per RCE pre-auth in Identity Manager

Altro da oggi