Impact
The Oracle Identity Manager product, specifically the legacy UI component, contains a flaw that an unauthenticated attacker can exploit over HTTP. Successful exploitation permits the attacker to take full control of the OIM instance, compromising confidentiality, integrity, and availability. The vulnerability is classified as a high‑severity remote code execution / authentication bypass flaw (CWE‑94 and CWE‑287).
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are impacted. These versions appear in the CPE list and are the only ones noted in the CNA report. No other releases are mentioned.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, so the precise exploitation probability is unknown, but the flaw is described as easily exploitable by an unauthenticated network attacker via HTTP. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only HTTP access to an OIM instance; no prior authentication is required.
OpenCVE Enrichment