Impact
The Oracle Identity Manager Legacy UI component suffers from an authentication and access control flaw (CWE‑284) that lets a low‑privileged attacker with network access via HTTP gain authorization and fully compromise the instance, giving the attacker control over confidentiality, integrity, and availability of the OIM service. The flaw is easily exploitable and results in a complete takeover of the Oracle Identity Manager deployment.
Affected Systems
Affected products are Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, both part of Oracle Fusion Middleware. The vulnerability does not extend beyond the Legacy UI component of these versions.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 signals high severity, while the EPSS score of less than 1% indicates a low current probability of exploitation. The flaw is not listed in the CISA KEV catalog; however, because it allows full system compromise, organizations are strongly encouraged to remediate. The likely attack vector is a simple HTTP request from a low‑privileged attacker who can reach the OIM instance, with no special privileges required beyond network connectivity.
OpenCVE Enrichment