Impact
The vulnerability is an access control flaw (CWE‑284) located in the Generic Unix Connector of Oracle Identity Manager Connector. It allows an unauthenticated attacker with physical or local network proximity to create, delete, or modify critical connector data and to trigger hangs or crashes that render the connector unavailable. The CVE description does not indicate confidentiality impact.
Affected Systems
Affected versions are Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0. The product is part of Oracle Fusion Middleware. The description notes that attacks may also have scope change and could affect additional products.
Risk and Exploitability
The CVSS 3.1 score of 8.0 denotes a high impact on integrity and availability. The EPSS score of less than 1% indicates a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector requires physical or adjacent network access to the hardware segment where the connector runs, the vulnerability is effectively local. Exploitation would involve gaining such proximity and exploiting the unchecked access control to perform privileged operations or cause denial of service.
OpenCVE Enrichment