Impact
A flaw in Oracle Identity Manager’s Core component removes authentication and allows an unauthenticated attacker to send HTTP requests that can bypass security controls. The vulnerability is exploited without any credentials and can lead to a complete takeover of the identity management instance. The high CVSS 3.1 base score of 9.8 reflects the catastrophic impact on confidentiality, integrity and availability.
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These releases are part of Oracle Fusion Middleware and are commonly used for enterprise identity and access management.
Risk and Exploitability
The attack vector is a straightforward HTTP request that can reach the vulnerable service from any network location with access to the exposed port. Because the flaw allows unauthenticated exploitation, it can be used by remote attackers to take over the entire system. Even though the EPSS score is below 1 %, the severity of the impact and the ease of exploitation mean that the vulnerability should be treated as critical. It is not listed in the CISA KEV catalog, but the combined risk warrants immediate attention.
OpenCVE Enrichment