Impact
A flaw in the Oracle Identity Manager legacy user interface allows an attacker with low privileged credentials and network connectivity over HTTP to gain full control of the service. The vulnerability involves improper authorization and lack of proper privilege checks, enabling the attacker to potentially modify, delete, or exfiltrate data and disrupt service availability. Due to changes in scope, a successful compromise may also affect additional products within the Oracle Fusion Middleware stack.
Affected Systems
The affected versions are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, which are deployed as part of Oracle Fusion Middleware and accessed through standard HTTP endpoints.
Risk and Exploitability
With a CVSS base score of 8.5, the flaw is considered high severity, affecting confidentiality, integrity, and availability. The EPSS score of less than 1% indicates low likelihood of exploitation at present, but the potential impact remains high. The vulnerability is not present in the CISA KEV catalog. Exploitation requires network access to the HTTP interface and an existing low‑privileged user account; once authenticated, the attacker can take over the entire service.
OpenCVE Enrichment