Impact
Oracle Identity Manager contains a REST WebServices vulnerability that allows a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data, as well as gain unauthorized read access to all data managed by the application. The flaw results in severe confidentiality and integrity impacts and is assessed with a CVSS 3.1 base score of 8.1, indicating high severity.
Affected Systems
Affected products are Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0.
Risk and Exploitability
The vulnerability can be exploited from any network location that can reach the OIM REST endpoint; a low‑privileged user does not need elevated credentials. Although the EPSS score is below 1 % and the flaw is not currently listed in the CISA KEV catalog, the high CVSS score and direct network attack surface mean that an adversary could persistently abuse the flaw if unpatched. The primary attack vector is via crafted HTTP requests to the vulnerable REST services.
OpenCVE Enrichment