Impact
The vulnerability in Oracle Identity Manager allows an attacker with low privilege who can reach the application over HTTP to take over the system. The flaw facilitates full control, thereby compromising confidentiality, integrity, and availability. The weakness is an improper authorization flaw (CWE‑284).
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected.
Risk and Exploitability
The CVSS Base Score of 8.8 indicates a high severity impact, while the EPSS score of less than 1% shows exploitation remains unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires only low privileged credentials and simple network access over HTTP, making it relatively easy to attempt in environments where the Identity Manager is exposed to the network.
OpenCVE Enrichment