Impact
An Oracle Identity Manager Connector vulnerability enables a high‑privileged attacker with network access over HTTPS to acquire control of the connector, allowing the attacker to create, delete, or modify critical data. The flaw impacts both confidentiality and integrity of all data accessible through the connector. The product controls sensitive identity information, so unauthorized changes could lead to data tampering or loss of trust in the system.
Affected Systems
Oracle Identity Manager Connector of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.1.0, are known to be affected. These versions are part of the Oracle Fusion Middleware suite, which supports various enterprise identity and access management components.
Risk and Exploitability
The CVSS 3.1 score of 8.7 indicates a high‑severity flaw that grants full control over connector data. Because the attack requires network access via HTTPS and a high‑privileged user context, the exploitation vector is likely remote but may need privileged or a compromised account. The EPSS score is < 1%, but the lack of listing in the CISA KEV catalog does not mitigate the risk; the vulnerability remains exploitable and can produce significant impact if the connector is exposed to untrusted networks.
OpenCVE Enrichment