Impact
A flaw in Oracle Identity Manager Connector permits an unauthenticated attacker who can reach the component over TLS to bypass authentication controls and assume full control of the connector. Because the vulnerability is exploitable without credentials or user interaction, an attacker could read, modify, or delete sensitive data, or perform arbitrary actions against the system, resulting in loss of confidentiality, integrity and availability.
Affected Systems
Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware, are affected.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates a high risk to confidentiality, integrity and availability. The EPSS score of < 1% shows a very low yet non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is network‑based TLS, where an unauthenticated actor can connect to the connector and achieve takeover, as reflected by AV:N, UI:N and PR:N in the vector.
OpenCVE Enrichment