An Unauthenticated Remote Code Execution vulnerability in the Identity Manager product of Oracle Fusion Middleware in versions 12.2.1.4.0 and 14.1.2.1.0. Allows unauthenticated attackers with network access via HTTP to compromise Identity Manager. Successful exploitation of this vulnerability can result in takeover of the Identity Manager instance.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. A partial list of potentially affected assets is outlined in this post.
References:

