Impact
The vulnerability resides in the Security component of Oracle Identity Manager and is classified as an access‑control flaw that can be exploited by a high‑privileged attacker who can reach the service over HTTP. Exploitation allows the attacker to create, delete, or modify critical data, thereby achieving unauthorized disclosure of information and integrity violations. The flaw threatens all data managed by the product and can potentially elevate impact to other components within the Oracle Fusion Middleware stack.
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware, are affected. The vulnerability is listed by Oracle as impacting these specific releases.
Risk and Exploitability
The CVSS 3.1 base score of 8.7 marks this as a high‑severity issue. The attack vector is network based with low effort (AV:N/AC:L), requires high privileges (PR:H), and needs no user interaction (UI:N), but the scope change (S:C) means the compromise could extend beyond the primary product. EPSS data indicates a very low exploitation probability (<1%) and the vulnerability is not listed in CISA KEV, indicating no known public exploits at this time, yet the combination of high severity and potential scope expansion warrants prompt remediation.
OpenCVE Enrichment