Impact
A vulnerability in the Oracle Identity Manager Connector product (Oracle Fusion Middleware) allows an attacker who has already logged on to the host machine carrying the connector to compromise the connector process. The flaw is described as an easily exploitable weakness that can lead to a takeover of Oracle Identity Manager Connector, resulting in loss of confidentiality, integrity, and availability for the connector’s function. The CVSS 3.1 base score of 7.8 reflects these impacts.
Affected Systems
The reported affected products are Oracle Identity Manager Connector, versions 12.2.1.4.0 and 14.1.2.1.0. No additional versions are listed.
Risk and Exploitability
The CVSS score indicates moderate to high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation in the wild. The CVE description notes a low privileged attacker with logon to the infrastructure as the required access, implying that exploitation is limited to local hosts where a user is already authenticated; no remote network attack vector is specified.
OpenCVE Enrichment