Impact
Oracle Identity Manager’s Legacy UI component contains an authentication and access‑control flaw that can be exploited by an attacker with low privileges and network access over HTTP. of the Oracle Identity Manager instance, resulting in complete loss of confidentiality, integrity, and availability for that system. The vulnerability is classified as CWE‑284, indicating a weakness in controlling access to resources.
Affected Systems
The product is Oracle Identity Manager. The vulnerability impacts version 12.2.1.4.0 and version 14.1.2.1.0.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 reflects a high‑severity flaw with complete impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a very low current probability of exploitation, but the flaw is not present in the CISA KEV catalog. Based on the description, the likely attack vector is a remote HTTP request from a low‑privileged attacker that takes advantage of missing or weak authentication controls to gain full control of the system.
OpenCVE Enrichment