Impact
The vulnerability lies in the Legacy UI component of Oracle Identity Manager. An attacker who only has standard network connectivity to the OIM server can send HTTP requests without authentication, enabling the creation, deletion or alteration of critical data and granting full read access to all data handled by the system. This results in significant confidentiality and integrity impacts, as the attacker can manipulate or exfiltrate sensitive information.
Affected Systems
Affected are Oracle Identity Manager releases 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware. Systems running these versions are at risk if the Legacy UI component remains exposed and accessible.
Risk and Exploitability
The CVSS score of 9.1 reflects severe confidentiality and integrity impact with no need for authentication. The EPSS score is below 1%, indicating low observed exploitation frequency to date, and the vulnerability is not yet listed in CISA’s KEV catalog. Nevertheless, the remote attack path via publicly reachable HTTP and the complete lack of authentication make it highly actionable; organizations with exposed OIM interfaces should prioritize remediation.
OpenCVE Enrichment