Impact
The Oracle Identity Manager Connector is vulnerable to a high‑impact flaw that allows a low‑privileged attacker with network access over TLS to compromise the service. Successful exploitation can result in a complete takeover, leading to loss of confidentiality, integrity and availability for the affected system.
Affected Systems
The vulnerability affects Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0, components within Oracle Fusion Middleware. Any deployment of these versions without the latest security patches is at risk.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, and the exploitability parameters (remote network, low privilege, zero user interaction, scope change) suggest that attacks are likely and capable of impacting multiple related products. The EPSS score of 0.00352 indicates a very low but non‑zero probability of exploitation, and the lack of a KEV listing does not diminish the risk posed by this far‑reaching flaw.
OpenCVE Enrichment