Impact
Oracle Identity Manager contains a vulnerability in its Security component that stems from missing authorization mechanisms (CWE‑269) and improper access control. The flaw allows an attacker with low privileges and network access via HTTP to execute arbitrary code, leading to a full takeover of the application and loss of confidentiality, integrity, and availability. The documented CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, reflecting a high impact from a network-facing attack.
Affected Systems
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware, are impacted by this vulnerability.
Risk and Exploitability
The base CVSS score of 8.8 indicates a severe threat, while the EPSS score of less than 1% shows a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. However, because exploitation requires only network connectivity over HTTP and no special privileges, an attacker who can reach the target could potentially compromise the system if mitigation steps are not applied.
OpenCVE Enrichment