Impact
The Oracle Identity Manager Installer component contains insufficient access controls that enable a local user with minimal privileges to execute installer code. Exploitation grants the attacker full control of the Identity Manager instance, affecting confidentiality, integrity, and availability. The vulnerability is a broken access control flaw that allows a local low‑privileged attacker to override system security.
Affected Systems
Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 from Oracle Corporation are affected. The flaw resides in the installer service that runs on the Identity Manager server.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 indicates high severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. Attackers only need local access with low privileges; no network connectivity is required. The flaw is not listed in the CISA KEV catalog, but within a compromised environment the risk remains substantial because a local attacker can gain full control of the Identity Manager instance.
OpenCVE Enrichment