Impact
The Oracle Identity Manager product, specifically the legacy UI component, contains a flaw that an unauthenticated attacker can exploit over HTTP. Successful exploitation permits the attacker to take full control of the OIM instance, compromising confidentiality, integrity, and availability. The vulnerability is classified as a high‑severity remote code execution / authentication bypass flaw (CWE‑284).
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are impacted. These versions are indicated by the provided CPE entries and are the only ones noted in the CNA report. No other releases are mentioned.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is < 1%, indicating a very low exploitation probability, but the flaw is described as easily exploitable by an unauthenticated network attacker via HTTP. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only HTTP access to an OIM instance; no prior authentication is required.
OpenCVE Enrichment