The product in this question is IFS Applications 10 UPD16.
A vulnerability scan (Nessus) performed by our infrastructure team flagged CVE-2026-21992 (OIM/OWSM) as "Critical" on our IFS middleware servers (in both test and production environments).
Upon investigation, I found an article stating that "IFS Cloud" is not affected by this vulnerability:
https://community.ifs.com/information-security-431/security-awareness-oracle-critical-rce-vulnerability-66302?tid=66302&fid=431
The article states the following:
"IFS solutions are not impacted by CVE-2026-21992, as they do not depend on the affected Oracle Fusion Middleware components."
Based on this, I would like to ask two questions:
1. Is it correct to assume that the information in this article applies equally to "IFS Applications 10" on-premises deployments?
2. Is it correct to understand that the OIM/OWSM components detected by the scan are actually unused/inactive on the IFS Middleware Server, and that IFS does not rely on the vulnerable REST Web Services / Web Services Security components?
As this also applies to our customers' production environments, we need to verify the accurate information.
I would appreciate your confirmation.