Impact
The vulnerability allows an unauthenticated attacker with network access via HTTP to exploit Oracle Identity Manager Connector and potentially gain unauthorized access to critical data or complete access to all data accessible through the connector. The flaw is based on improper handling of authentication and authorization, exposing sensitive information to anyone who can reach the connector’s exposed interfaces, and it is categorized as a confidentiality impact.
Affected Systems
The vulnerability affects Oracle Corporation’s Oracle Identity Manager Connector component of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.1.0. The impacted area is the PeopleSoft Applications component that utilizes the connector.
Risk and Exploitability
The severity is high, with a CVSS v3.1 score of 8.6 and an EPSS of less than 1 %. The vulnerability is not catalogued in CISA’s KEV. Based on the described interaction, the attack vector is likely an unauthenticated external HTTP request that can be made over the network to the connector’s exposed interfaces.
OpenCVE Enrichment