Skip to main content
Solved

Does the CVE-2026-21992 (OIM/OWSM) vulnerability affect IFS Applications 10?

  • August 20, 2026
  • 2 replies
  • 44 views

Forum|alt.badge.img+2

The product in this question is IFS Applications 10 UPD16.

 

A vulnerability scan (Nessus) performed by our infrastructure team flagged CVE-2026-21992 (OIM/OWSM) as "Critical" on our IFS middleware servers (in both test and production environments).


Upon investigation, I found an article stating that "IFS Cloud" is not affected by this vulnerability:
https://community.ifs.com/information-security-431/security-awareness-oracle-critical-rce-vulnerability-66302?tid=66302&fid=431

The article states the following:
"IFS solutions are not impacted by CVE-2026-21992, as they do not depend on the affected Oracle Fusion Middleware components."

Based on this, I would like to ask two questions:

1. Is it correct to assume that the information in this article applies equally to "IFS Applications 10" on-premises deployments?

2. Is it correct to understand that the OIM/OWSM components detected by the scan are actually unused/inactive on the IFS Middleware Server, and that IFS does not rely on the vulnerable REST Web Services / Web Services Security components?

 

As this also applies to our customers' production environments, we need to verify the accurate information.


I would appreciate your confirmation.

Best answer by Hansi Bandara

Thank you for your query.

IFS has assessed CVE-2026-21992 and can confirm that IFS solutions are not impacted by this vulnerability, as they do not depend on the affected Oracle Fusion Middleware components referenced. (Security Awareness: Oracle Critical RCE Vulnerability)

Please find below the further clarifications and guidance relating to the queries raised.

1. Does the statement also apply to IFS Applications 10 on-premises deployments?

Yes. The assessment relates to IFS solutions and their use of Oracle middleware components. Based on IFS's evaluation of CVE-2026-21992, IFS Applications 10 does not rely on the affected Oracle Fusion Middleware functionality identified in the vulnerability advisory. Therefore, IFS do not consider IFS Applications 10 to be impacted by CVE-2026-21992.

However, if any customer operates under a Remote Deployment model, their environment may include customer-specific customizations, and additional components that fall outside the standard IFS Managed Cloud deployment scope. Additionally, the responsibility for securing, maintaining, and managing the remotely deployed infrastructure remains with the customer.

 

2. Does the detection of OIM/OWSM components indicate that these components are unused by IFS, and that IFS does not rely on the vulnerable REST Web Services / Web Services Security functionality?

IFS solutions do not depend on the Oracle Fusion Middleware components affected by CVE-2026-21992 and are therefore not considered vulnerable to this issue.

Recommended Actions 

2 replies

Forum|alt.badge.img+3
  • Do Gooder (Employee)
  • Answer
  • August 28, 2026

Thank you for your query.

IFS has assessed CVE-2026-21992 and can confirm that IFS solutions are not impacted by this vulnerability, as they do not depend on the affected Oracle Fusion Middleware components referenced. (Security Awareness: Oracle Critical RCE Vulnerability)

Please find below the further clarifications and guidance relating to the queries raised.

1. Does the statement also apply to IFS Applications 10 on-premises deployments?

Yes. The assessment relates to IFS solutions and their use of Oracle middleware components. Based on IFS's evaluation of CVE-2026-21992, IFS Applications 10 does not rely on the affected Oracle Fusion Middleware functionality identified in the vulnerability advisory. Therefore, IFS do not consider IFS Applications 10 to be impacted by CVE-2026-21992.

However, if any customer operates under a Remote Deployment model, their environment may include customer-specific customizations, and additional components that fall outside the standard IFS Managed Cloud deployment scope. Additionally, the responsibility for securing, maintaining, and managing the remotely deployed infrastructure remains with the customer.

 

2. Does the detection of OIM/OWSM components indicate that these components are unused by IFS, and that IFS does not rely on the vulnerable REST Web Services / Web Services Security functionality?

IFS solutions do not depend on the Oracle Fusion Middleware components affected by CVE-2026-21992 and are therefore not considered vulnerable to this issue.

Recommended Actions 


Forum|alt.badge.img+2
  • Author
  • Do Gooder (Partner)
  • August 31, 2026

Thank you for your response.
I am relieved to hear that IFS Applications 10 (uncustomized) is not affected by this vulnerability. I will convey this to the customer.

Regarding the item listed below from your answer to point 2, I will contact the Service Center to verify it, just to be certain.