Impact
A flaw in the Oracle Identity Manager legacy UI implements improper access control that allows an attacker with low privilege to use the public HTTP interface to gain full control of the identity management system. The vulnerability requires a low‑privileged attacker with network access via HTTP and results in complete compromise of confidentiality, integrity, and availability, enabling an attacker to read, modify, delete identity data and execute privileged operations. The weakness is classified as ‘CWE‑284: Improper Access Control’.
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These releases are part of Oracle Fusion Middleware and expose a legacy UI component over standard HTTP endpoints. Vulnerable installations are those that allow unauthenticated or low‑privilege users to reach the legacy UI without additional network restriction.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity. The attack vector is remote over the network (AV:N) with low effort (AC:L), low privilege (PR:L) and no user interaction (UI:N). The EPSS score is less than 1% and the CVE is not listed in CISA’s KEV catalog, but the low exploitation probability does not reduce the risk; exposed deployments are susceptible to remote takeover.
OpenCVE Enrichment