Impact
This vulnerability allows a low‑privileged attacker who can reach the Oracle Identity Manager Connector over HTTP to take full control of the component. The flaw resides in the Mainframe Connectors of the Identity Manager Connector product. Exploitation leads to complete confidentiality, integrity, and availability compromise of the affected service, potentially propagating further impact to other Oracle Fusion Middleware products whose scope may be altered. The weakness results in uncontrolled execution and takeover of the connector.
Affected Systems
Oracle Corporation’s Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These are part of the Oracle Fusion Middleware stack and are reachable via standard HTTP interfaces.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score is below 1 % but not zero, meaning exploitation is unlikely at this time but could occur if attackers mount a targeted campaign. The vulnerability is not listed in CISA’s KEV catalog, yet the high impact and low‑privilege attack vector make it a priority for remediation. An attacker only needs network access to the HTTP endpoint, minimal privileges, and the ability to send crafted requests to successfully compromise the service.
OpenCVE Enrichment