Impact
A vulnerability in Oracle Identity Manager Connector allows a user who has already logged onto the host machine to take over the connector process completely. The flaw permits the attacker to read, modify, and disrupt the connector’s confidential data, alter its configuration, and potentially run arbitrary code in the context of the connector service. Because the vulnerability has high confidentiality, integrity, and availability impacts, a successful exploit can disrupt federation and identity management functionality for an entire organization.
Affected Systems
The affected products are Oracle Identity Manager Connector, versions 12.2.1.4.0 and 14.1.2.1.0. No other versions or variants are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 indicates a moderate to high severity while the EPSS score of less than 1 % reflects a low probability of exploitation in the wild. The vulnerability is not yet listed in CISA’s KEV catalog. According to the description, an attacker must have local logon to the infrastructure where the connector runs; with such access, exploitation is straightforward and requires no special privileges beyond those available to the user. The lack of a network-facing attack vector makes remote exploitation unlikely, but any compromise of the local machine effectively grants full control over the connector.
OpenCVE Enrichment