Impact
A flaw in the OIM Legacy UI component of Oracle Identity Manager allows a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data, and to gain unauthorized access to all data within the system. The vulnerability can be leveraged to bypass access controls and compromise confidentiality and integrity of the data. The vulnerability description identifies this as an “easily exploitable” weakness enabling unauthorized manipulation of Oracle Identity Manager data.
Affected Systems
Affected products are Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, as identified by the provided CPE entries. These are subset of Oracle Fusion Middleware deployments that run the OIM Legacy UI component.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates a high risk of compromise, but the EPSS score is < 1%, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, the network‑accessible nature of the flaw means a low‑privileged attacker could exploit it by issuing HTTP requests to the OIM Legacy UI endpoints, seeing that the risk remains actionable.
OpenCVE Enrichment