Impact
The vulnerability allows an unauthenticated attacker who has access to the physical network segment where the Oracle Identity Manager Connector runs to compromise the component. Successful exploitation can lead to complete takeover, giving the attacker full control over the connector, potentially exposing sensitive identity data and enabling further lateral movement within the organization. The flaw carries a high severity risk with a CVSS 3.1 score of 7.5, indicating significant confidentiality, integrity, and availability impacts.
Affected Systems
The Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These versions are part of Oracle Fusion Middleware and provide connectivity between identity management systems and various back‑end resources. Operators running either of these releases should immediately verify their deployment and plan for the application of the vendor‑issued fix.
Risk and Exploitability
The potential for exploitation requires only local physical access and no authentication, as the attack vector requires the attacker to be on the same physical network segment where the connector runs. The CVSS vector (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms that the flaw is remotely exploitable on the adjacent network and leads to complete compromise. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog at this time. The high CVSS base score of 7.5 and the potential for complete takeover warrant prompt remediation.
OpenCVE Enrichment