Impact
Oracle Identity Manager Connector is vulnerable to a remote LDAP-based privilege escalation that can lead to complete takeover of the connector. The flaw resides in the Microsoft Active Directory component of the connector and allows an attacker with high privileges and network access to LDAP traffic to bypass the connector's authentication controls. Successful exploitation would compromise the confidentiality, integrity, and availability of the connector, potentially exposing sensitive identity data and disrupting access for legitimate users.
Affected Systems
Affected vendors: Oracle Corporation; product: Oracle Identity Manager Connector. Versions 12.2.1.4.0 and 14.1.2.1.0 are listed as vulnerable. These versions are part of the Oracle Fusion Middleware suite and target the Microsoft Active Directory integration component.
Risk and Exploitability
The CVSS 3.1 base score is 8.0, indicating high severity. The attack vector, requiring network access (AV:N) and high privilege (PR:H), and a scope change (S:C) suggests that exploitation could affect multiple systems within an environment. Although the EPSS score is < 1%, the entry is not listed in the CISA KEV catalog, the presence of a scope change and the need for high‑privilege LDAP actions imply a realistic risk of broader compromise. The likely attack path involves an attacker issuing carefully crafted LDAP queries to the connector and leveraging the flaw to gain administrative control, potentially taking over the entire service.
OpenCVE Enrichment