Impact
The vulnerability in Oracle Identity Manager Connector allows an attacker who can reach the same physical communication segment as the connector to compromise the component without authentication. Exploitation results in complete control of the connector, exposing confidentiality, integrity, and availability. The weakness is identified as CWE‑284, reflecting an improper access control issue.
Affected Systems
Oracle Identity Manager Connector for Oracle Fusion Middleware, versions 12.2.1.4.0 and 14.1.2.1.0. The affected binaries run on hardware where the connector is installed and communicate over a local network segment.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an adjacent or local network segment where the attacker has physical or network access to the connector’s communication interface. Successful exploitation yields full control of the connector, allowing further attacks on the connected identity management system.
OpenCVE Enrichment