Impact
A flaw in Oracle Identity Manager Connector’s authentication process (CWE‑306) allows an attacker with low privileges and network access over HTTP to bypass required checks and gain full control of the connector. If exploited, the attacker can compromise confidentiality, integrity, and availability of the connector service, effectively taking it over.
Affected Systems
Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware. A scope change indicates that successful exploitation may also impact other related Oracle products accessed through the connector.
Risk and Exploitability
The CVSS v3.1 Base Score is 9.9 with network-based, low-complexity, low-privilege attack vector, no user interaction, and a scope change. The EPSS score is less than 1 % and the issue is not listed in the CISA KEV catalog. Because a network attacker can reach the affected service over HTTP, the risk to a potential attacker who can access the endpoint remains high.
OpenCVE Enrichment