Impact
The Oracle Identity Manager Connector is affected by a vulnerability that permits a low-privileged attacker with network access through TLS to compromise the connector, potentially resulting in complete takeover and providing unrestricted confidentiality, integrity, and availability impact.
Affected Systems
Affected products are Oracle Identity Manager Connector from Oracle Corporation. Versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable.
Risk and Exploitability
The vulnerability scores 9.9 on CVSS 3.1, with the exploit vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating that it is remotely exploitable, requires only low privilege, and grants full control over the component. EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the issue is not listed in the CISA KEV catalog. Because the attack vector is network based and the scope is changed, an attacker could leverage the vulnerability from any position that can reach the connector over TLS, potentially affecting other applications that rely on it. The high severity and lack of a publicly available mitigation mean immediate action is required.
OpenCVE Enrichment