Impact
A flaw in the Oracle Identity Manager Connector’s core component allows an unauthenticated attacker to create, full unauthorized access to all data accessible through the connector. The weaknessCWE‑284). No remote code execution or denial of service is disclosed, but confidentiality and integrity can be compromised for identity information.
Affected Systems
Oracle Identity affected. The vulnerable versions are 12.2.1.4.0 and 14.1.2.1.0, part of versions, if exposed to network traffic, are at risk.
Risk and Exploitability
The CVSS v3.1 base score of 8.7 demonstrates high severity with significant confidentiality and integrity impact. The EPSS score of less than 1% indicates a current very low likelihood of observed exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers only require network access and no authentication; the flaw can be leveraged over TCP to manipulate note means exploitation could affect other linked Oracle products.
OpenCVE Enrichment