Impact
Unauthenticated attackers with HTTP network access can compromise the Oracle Identity Manager Legacy UI, allowing full takeover of the system. The vulnerability is caused by authentication bypass weaknesses (CWE‑287 and CWE‑306) that allow an attacker to authenticate without credentials. This leads to exposure of all confidentiality, integrity, and availability aspects and is scored 9.8 on the CVSS 3.1 scale.
Affected Systems
Oracle Corporation’s Oracle Identity Manager product versions 12.2.1.4.0 and 14.1.2.1.0 are affected.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, yet the CVSS score reflects that an attacker who succeeds will gain complete control. The vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires only unauthenticated HTTP access to the Legacy UI and does not demand privileged credentials or additional preconditions.
OpenCVE Enrichment