Impact
The vulnerability in Oracle Identity Manager’s Legacy UI allows an unauthenticated attacker with network access to create, delete, or modify critical data and to read all accessible data, effectively granting full administrative control. This flaw is a classic example of improper access control (CWE‑284) that directly affects confidentiality and integrity, rating a CVSS 3.1 base score of 9.1.
Affected Systems
Affected products are Oracle Identity Manager, version 12.2.1.4.0 and 14.1.2.1.0, as distributed under Oracle Fusion Middleware. No other vendors or product families are listed.
Risk and Exploitability
The vulnerability is easily exploitable over HTTP without authentication, though the EPSS score of less than 1% indicates a low overall likelihood of exploitation in the wild. It is not catalogued in CISA’s KEV list. Attackers who succeed can gain unrestricted access to all data managed by Oracle Identity Manager.
OpenCVE Enrichment