Impact
The issue affects Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0. A local low‑privileged attacker who can log on to the hardware that hosts the connector can exploit the vulnerability when a single additional person provides user interaction. The exploit permits the attacker to modify or delete access‑control settings and subsequently create, delete, or alter critical data, exposing both confidentiality and integrity of all data reachable through the connector.
Affected Systems
Oracle Identity Manager Connector, part of Oracle Fusion Middleware’s Core component. The documented affected releases are 12.2.1.4.0 and 14.1.2.1.0. Although the vulnerability resides in the connector, subsequent operations may affect other connected Oracle products, as the scope can change from the connector to the broader system.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates high severity with significant confidentiality and integrity impact. The EPSS score is 0.00094 (0.094%), indicating a very low probability of exploitation. The local attacker requirement combined with a need for separate user interaction limits the ease of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no documented exploitation yet. Nonetheless, because success grants full data access and potential influence over additional products, the overall risk remains serious and warrants proactive attention.
OpenCVE Enrichment