Impact
The vulnerability is an access control flaw (CWE‑284) that allows an unauthenticated attacker with network access to an Oracle Identity Manager Connector instance to gain unauthorized access to all data managed by the connector. The flaw can lead to the disclosure of sensitive information or complete compromise of data handled by the connector, creating a significant confidentiality risk.
Affected Systems
Affected are Oracle Corporation’s Oracle Identity Manager Connector product in Fusion Middleware, specifically the versions 12.2.1.4.0 and 14.1.2.1.0.
Risk and Exploitability
According to the CVSS 3.1 base score of 8.6, the vulnerability is high severity with a substantial confidentiality impact. The EPSS score of less than 1% indicates a low and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote via HTTP to the connector’s interface, and the flaw’s scope change enables attackers to impact other components beyond the connector itself. Successful exploitation would provide an attacker full read access to protected data.
OpenCVE Enrichment