Impact
The Oracle Identity Manager Legacy UI component contains an improper access control flaw that can be exploited by an attacker with only low privileges who can reach the system over the network via Remote Method Invocation (RMI). Successful exploitation enables the attacker to execute arbitrary code and ultimately take full control of Oracle Identity Manager. The impact spans confidentiality, integrity, and availability because the attacker can exfiltrate data, modify or delete identities, and disrupt services.
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These releases are listed in the vendor’s security alert and are confirmed by the CPE entries. No other vendors or product lines are identified as affected for this specific vulnerability.
Risk and Exploitability
With a CVSS 3.1 base score of 9.9 this vulnerability is classified as Critical. The EPSS score of less than 1% indicates a currently low probability of exploitation, and it is not included in the CISA Known Exploited Vulnerabilities catalog. The vulnerability’s scope change suggests that compromise of the Legacy UI may also impact other components of the Oracle Identity Manager stack, potentially widening the attack surface. The attack vector is inferred to be network-based via RMI, requiring the attacker to contact the exposed RMI service, but only a low level of initial privileges is needed to succeed.
OpenCVE Enrichment