Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).
Published: 2026-07-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an access control flaw (CWE‑284) located in the Generic Unix Connector of Oracle Identity Manager Connector. It allows an unauthenticated attacker with physical or local network proximity to create, delete, or modify critical connector data and to trigger hangs or crashes that render the connector unavailable. The CVE description does not indicate confidentiality impact.

Affected Systems

Affected versions are Oracle Identity Manager Connector 12.2.1.4.0 and 14.1.2.1.0. The product is part of Oracle Fusion Middleware. The description notes that attacks may also have scope change and could affect additional products.

Risk and Exploitability

The CVSS 3.1 score of 8.0 denotes a high impact on integrity and availability. The EPSS score of less than 1% indicates a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector requires physical or adjacent network access to the hardware segment where the connector runs, the vulnerability is effectively local. Exploitation would involve gaining such proximity and exploiting the unchecked access control to perform privileged operations or cause denial of service.

Generated by OpenCVE AI on August 4, 2026 at 03:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a non‑affected version as soon as possible
  • Restrict physical and adjacent network access to the connector servers; use network segmentation and enforce strict authentication for all connections
  • Enforce strict access control: review and tighten ACLs so that only authorized users can perform privileged operations, and apply the principle of least privilege
  • Monitor audit logs for unauthorized data modifications or repeated crashes and investigate anomalies promptly

Generated by OpenCVE AI on August 4, 2026 at 03:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Oracle Identity Manager Connector Access Control Flaw Enabling Unauthorized Data Operations and Denial of Service

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Privilege Escalation and Denial of Service via Physical Network Access in Oracle Identity Manager Connector

Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Privilege Escalation and Denial of Service via Physical Network Access in Oracle Identity Manager Connector
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.0 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T14:07:44.784Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60533

cve-icon Vulnrichment

Updated: 2026-07-24T18:08:49.169Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses