Impact
Oracle Identity Manager’s Legacy UI contains an access control flaw that permits an attacker with high privileges and network access via HTTP to read, modify, or delete data that should be protected. This flaw can grant an adversary full access to critical identity data, leading to potential compromise of other connected systems if the authority scope is broadened.
Affected Systems
The vulnerability exists in Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 and targets the Legacy UI component of the Oracle Fusion Middleware suite.
Risk and Exploitability
The CVSS base score of 7.6 denotes a high impact on confidentiality, with a low integrity effect. The EPSS score of less than 1% indicates a very low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is network‑based (HTTP) and requires an attacker with high privileges. Successful exploitation could lead to unauthorized data access or full compromise of all Identity Manager accessible data.
OpenCVE Enrichment