Impact
The vulnerability in Oracle Identity Manager Connector allows an attacker who has access to the physical communication segment to gain unauthenticated control over the component, potentially executing arbitrary code and taking over the connector. This flaw is presented as an Improper Authentication issue, as the connector does not enforce authentication for traffic originating from the local physical network, which can be exploited by a low-entropy, high-complexity attack path. The result is a significant breach of confidentiality, integrity, and availability for the Managed Identity Operator and related user data.
Affected Systems
Affected are Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 which run in Oracle Fusion Middleware. Any system where these connectors are deployed, particularly those connected to local hardware or network segments with unchecked physical access, is at risk.
Risk and Exploitability
The CVSS score of 8.3 (AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates a high severity for remote attackers, but the EPSS score of <1% shows a low current exploit probability. It is not listed in the CISA KEV catalog. The path requires the attacker to physically interact or be near the hardware segment that hosts the connector, but once done, no explicit authentication is needed, and the risk extends beyond the connector to other product components due to scope change.
OpenCVE Enrichment