Impact
Oracle Identity Manager’s Legacy UI contains an authentication bypass that allows an attacker with network access to an unprotected HTTP endpoint to execute arbitrary actions and ultimately take possession of the entire OIM instance. The weakness is a failure to protect authentication credentials, identified as CWE‑306, and the CVSS 3.1 Base Score of 9.8 reflects severe confidentiality, integrity, and availability impacts.
Affected Systems
The vulnerability affects Oracle Corporation’s Oracle Identity Manager product, specifically versions 12.2.1.4.0 and 14.1.2.1.0. These are the only supported releases listed by the CNA.
Risk and Exploitability
The CVSS score indicates a critical threat, but the EPSS score of less than 1% suggests the vulnerability is currently unlikely to be exploited in the wild; however, it is listed as not yet in the CISA KEV catalog. Attackers can exploit the flaw remotely over HTTP without authentication, meaning any user with network reach to the OIM web interface can take over the system.
OpenCVE Enrichment