Impact
The vulnerability resides in the Oracle Identity Manager Legacy UI component of Oracle Fusion Middleware and is caused by improper access control and authentication weaknesses (CWE-306). It permits an unauthenticated attacker with network connectivity to the T3 or IIOP services to gain full control over the Oracle Identity Manager instance. Successful exploitation results in a complete takeover, with full loss of confidentiality, integrity, and availability of the system and its data.
Affected Systems
Affected products are Oracle Identity Manager version 12.2.1.4.0 and 14.1.2.1.0. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; no credentials, privileges, or user interaction are required beyond establishing a connection to the vulnerable T3/IIOP ports.
OpenCVE Enrichment