Impact
An unauthenticated attacker who can reach the Oracle Identity Manager Connector over HTTP can trigger a privilege escalation flaw, allowing arbitrary code execution on the service. The vulnerability, identified as CWE-269, results in loss of confidentiality, integrity, and availability for the affected product and grants an attacker full control over the connector, potentially serving as a foothold for lateral movement.
Affected Systems
Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 are impacted. These releases belong to Oracle Fusion Middleware and are typically deployed within PeopleSoft application environments. Any installation that exposes the connector’s HTTP interface is vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 indicates critical severity, while the EPSS score of less than 1 % suggests that widespread real‑world exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known exploitation has been documented yet. Nevertheless, the flaw is easily exploitable once the connector is reachable over HTTP, and the attacker does not need authentication to compromise the service.
OpenCVE Enrichment