Impact
An unauthenticated network attacker can send specially crafted HTTP requests to the management interface of Oracle Identity Manager Connector, allowing full takeover of the component. The vulnerability permits an attacker to execute arbitrary code, modify configuration, and access or alter sensitive identity data, leading to total loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware used in PeopleSoft applications, are impacted.
Risk and Exploitability
The CVSS 3.1 score of 9.8 marks this flaw as critical, and its exploitability is low effort because it does not require authentication or authorized credentials; an attacker only needs network access to the connector’s HTTP interface. The EPSS score of less than 1% indicates that active exploitation is currently rare, and the flaw is not listed in the CISA KEV catalog, but the combination of a high CVSS score and unrestricted access points to a high practical risk for exposed systems.
OpenCVE Enrichment