Impact
A flaw in the Oracle Identity Manager Connector’s core component permits an unauthenticated attacker with network access via TCP to create, delete, or modify critical data accessible through the connector. This unauthorized activity compromises both confidentiality and integrity of that data, but does not provide remote code execution or denial of service. The weakness is identified as CWE-284, an Authorization problem.
Affected Systems
The vulnerability affects Oracle’s Identity Manager Connector, specifically versions 12.2.1.4.0 and 14.1.2.1.0, when those instances are reachable over the network. Systems with the connector exposed to external TCP traffic are susceptible to exploitation.
Risk and Exploitability
The CVSS v3.1 base score of 8.7 signals high severity, with significant confidentiality and integrity impact. The EPSS score below 1% indicates a very low likelihood of observed exploitation at present. The flaw is not listed in the CISA KEV catalog. Attackers need only unauthenticated network access to the connector’s TCP interface to leverage the vulnerability, which can also lead to unauthorized changes or deletion of critical data and may affect other Oracle products that rely on the connector.
OpenCVE Enrichment