Impact
Oracle Identity Manager’s Legacy UI contains an access control flaw that allows an attacker with high privileges, who can reach the system over HTTP, to gain unauthorized read or write access to critical data. This may allow complete compromise of all data accessible through Oracle Identity Manager and, depending on the environment, can potentially affect other products as the authority scope is changed.
Affected Systems
The flaw is present in Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0, specifically targeting the Legacy UI component. These versions are part of the Oracle Fusion Middleware suite and are used for identity, access, and user management within enterprise environments.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high impact on confidentiality with low integrity damage. The EPSS score, listed as less than 1%, signals a very low current exploitation likelihood, and the vulnerability is not yet cataloged as a known exploited vulnerability. Still, the attack vector is network‑based (HTTP) and requires high privilege, meaning that if an attacker gains network access, they can use this weakness to fully compromise Oracle Identity Manager data.
OpenCVE Enrichment