Impact
Based on the description, it is inferred that the vulnerability stems from improper access control in the OIM Legacy UI component, allowing a low‑privileged attacker with network access to send crafted HTTP requests and achieve a full takeover of the Oracle Identity Manager system. This would compromise confidentiality, integrity, and availability. The CVSS 3.1 base score is 8.8, indicating a high severity risk to affected deployments.
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The affected component is the Legacy UI of the Oracle Fusion Middleware OIM product.
Risk and Exploitability
Based on the description, the likely attack vector is network access via HTTP to the OIM Legacy UI component, where a low‑privileged attacker can send crafted requests exploiting improper access control, potentially gaining administrator‑level access and allowing full takeover of the system. The exploit requires only network connectivity and a low‑privileged credential, making it relatively easy to execute. The EPSS score is < 1%, indicating a low probability of exploitation in the wild, but the high CVSS score and absence from the KEV catalogue still suggest that when exploitation does occur, it carries significant risk.
OpenCVE Enrichment