Impact
The flaw in Oracle Identity Manager Connector is a high‑privilege access control weakness that allows an attacker who already has elevated network access via HTTP to create, delete, or modify critical data. The vulnerability is classified as CWE‑284, meaning it enables an attacker to elevate privileges beyond their intended permissions, resulting in confidentiality and integrity loss for the connector’s data stores.
Affected Systems
Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0, shipped as part of Oracle Fusion Middleware and used by PeopleSoft Applications, are affected. The product is accessed over HTTP and forms part of a broader identity management architecture.
Risk and Exploitability
The CVSS 3.1 base score is 7.7, indicating serious confidentiality and integrity impacts but no availability compromise. The EPSS score is reported as less than 1 %, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires network access to the HTTP endpoint and a high‑privilege account; once achieved, the attacker can impact the connector and, due to a scope change, potentially affect other connected components.
OpenCVE Enrichment