Impact
The Oracle Identity Manager Connector product contains a local privilege escalation flaw that allows a low‑privileged user who can log on to the infrastructure hosting the connector to compromise the service. Successful exploitation results in full takeover of the connector, with confidentiality, integrity, and availability all impacted as described by the CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability is deemed easily exploitable due to its low attack complexity and the minimal prerequisites of local logon and low privilege. It represents a high‑severity flaw capable of delivering complete control over the identity management infrastructure.
Affected Systems
Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These versions run within Oracle Fusion Middleware and target the core component of the connector. The flaw does not affect higher or older releases beyond those specified.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity rating. The EPSS score is <1% which indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local with no user interaction required, making it a concern primarily for users with low‑level local accounts or compromised credentials. Because the flaw allows a total takeover of the connector, the risk to confidentiality, integrity, and availability is significant for any environment relying on the affected versions.
OpenCVE Enrichment