Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
302 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 17/6/2026 | 17/6/2026 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager | 17/6/2026 | 17/6/2026 | Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Mainframe Connectors). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager… | |
| Analizada | Alta (7.5) | 0.35% | — | Oracle Identity Manager | 17/6/2026 | 17/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager | 17/6/2026 | 18/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Identity Manager. While the vulnerability is in… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Identity Manager | 17/6/2026 | 18/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Identity Manager | 17/6/2026 | 18/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this… | |
| Analizada | Media (5.9) | 0.23% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Identity Manager… | |
| Analizada | Alta (7.5) | 0.47% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Media (5.9) | 0.33% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector.… | |
| Analizada | Media (5.9) | 0.33% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Identity Manager | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Pendiente de análisis | Alta (8.4) | 0.29% | — | Opentext Identity ManagerAI | 27/3/2026 | 7/10/2026 | Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1). | |
| Analizada | Crítica (9.8) | 1.0% | — | Oracle Identity ManagerOracle WEB Services Manager | 20/3/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability… | |
| Analizada | Crítica (9.8) | 89% | ⚠ Explotación activa💥 Exploit | Oracle Identity Manager | 21/10/2025 | 17/6/2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks… | |
| Aplazada | Media (6) | 0.12% | — | Beta80 Life 1ST Identity ManagerAI | 19/3/2025 | 17/6/2026 | Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerabilities in Beta80 "Life 1st Identity Manager" enable an attacker with access to password hashes to bruteforce user passwords or find a collision… | |
| Aplazada | Crítica (10) | 0.39% | — | Opentext Identity Manager Advanced EditionAI | 5/3/2025 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager… | |
| Aplazada | Crítica (9.9) | 0.68% | — | Oneidentity Identity ManagerAI | 24/1/2025 | 17/6/2026 | In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected. | |
| Analizada | Alta (7.5) | 0.37% | — | Netiq Identity Manager Rest Driver | 12/9/2024 | 17/6/2026 | Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200. | |
| Analizada | Media (5.5) | 0.14% | — | Opentext Identity Manager Azuread Driver | 12/9/2024 | 17/6/2026 | A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0 | |
| Modificada | Media (6.1) | 0.35% | — | Vmware Identity ManagerVmware Workspace ONE AccessVmware Cloud FoundationVmware Identity Manager Connector | 30/5/2023 | 17/6/2026 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | |
| Modificada | Media (6.1) | 0.51% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application | |
| Modificada | Media (6.1) | 0.51% | — | Broadcom Symantec Identity Governance AND AdministrationBroadcom Symantec Identity Manager | 26/1/2023 | 17/6/2026 | User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses. |