Impact
The vulnerability affects the Oracle Identity Manager Connector component, allowing an attacker who can physically connect to the hardware to create, delete, or modify access permissions for critical data. This bypasses normal authorization controls, leading to confidentiality and integrity compromises. Both affected processors can also be impacted due to the scope change, potentially giving attackers broader system access.
Affected Systems
Oracle Identity Manager Connector versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. Users running these releases should immediately verify and correct the installation.
Risk and Exploitability
The CVSS v3.1 score of 9.3 highlights the severe impact of the flaw. Although the EPSS score is less than 1%, indicating a low probability of widespread exploitation based on current data, the lack of a KEV listing does not reduce the need for urgent remediation. The attack requires physical access to the hardware, meaning it is an AV:A vector with local execution, no privilege or user interaction needed. Once accessed, the attacker can gain high-impact confidentiality and integrity effects on the system and related products.
OpenCVE Enrichment