Impact
A flaw within the Core component of Oracle Identity Manager allows an attacker who possesses only low-level privileges and network access on the T3 or IIOP protocols to compromise the system. Exploitation of this vulnerability can lead to full system takeover, providing the attacker with complete control. The weakness results in confidentiality, integrity, and availability damage with a CVSS 3.1 base score of 8.8, indicating high severity.
Affected Systems
Oracle Corporation's Identity Manager product, specifically versions 12.2.1.4.0 and 14.1.2.1.0, is affected. These are part of the Oracle Fusion Middleware suite and rely on the Core component for identity management.
Risk and Exploitability
The CVSS score reflects critical impact across all dimensions, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to be able to reach the system over the network and use the T3 or IIOP ports, indicating a remote network‑based attack vector that is easily exploitable by users with low privileges. These characteristics raise the risk to organizations relying on OIM for identity and access control.
OpenCVE Enrichment