Impact
Oracle Identity Manager’s Legacy UI component contains a flaw that a user with low privileges can exploit when connected to the service over the T3 or IIOP protocols. An attacker can use this vulnerability to bypass normal authentication checks and gain full control of the system. The success of the attack would give the attacker the ability to read sensitive data, modify or delete configuration, and ultimately take over the entire Identity Manager installation. The security impact is severe, affecting confidentiality, integrity, and availability of the service.
Affected Systems
The affected entity is Oracle Corporation’s Oracle Identity Manager. Versions 12.2.1.4.0 and 14.1.2.1.0 are listed as vulnerable. The Legacy UI component of these releases is the attack surface.
Risk and Exploitability
The CVSS v3.1 base score is 8.8, reflecting a high severity risk. The EPSS score of 0.00432 indicates an extremely low probability of exploitation, yet the high base score indicates that when it is exploited, the impact is severe. The vulnerability is not yet listed in the CISA KEV catalog, so there are no known deployments exploited in the wild. Attackers can reach the vulnerable service from any host with network access to the T3 or IIOP port, and the low privileged requirement means no elevated rights are needed; no user interaction is required beyond establishing a network connection.
OpenCVE Enrichment