Impact
The flaw in Oracle Identity Manager Connector enables an unauthenticated attacker who can reach the physical communication segment attached to the hardware where the connector runs to compromise the component. While the vendor description states only that a takeover is possible, based on the CVSS 3.1 vector (AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) it is inferred that the attacker may gain full control of the connector, effectively representing a component takeover that could threaten confidentiality, integrity and availability of managed identities.
Affected Systems
Affected are Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware. Any deployment where these connector packages are installed and exposed to a local or adjacent network segment constitutes a risk area, especially in environments lacking strict physical access controls.
Risk and Exploitability
The CVSS base score of 8.3 marks the vulnerability as high severity, but the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not yet listed in the CISA KEV catalog. Exploitation requires an attacker to have physical or adjacent network access, after which authentication is not required; the vulnerability can change scope and potentially affect other products in the environment.
OpenCVE Enrichment