Impact
A vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware allows a high privileged attacker with network access via HTTP to compromise the application, resulting in confidentiality, integrity and availability loss. The flaw is described as easily exploitable and is capable of leading to full takeover of the Connector. The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, indicating a significant risk to all security properties.
Affected Systems
Oracle Corporation’s Oracle Identity Manager Connector is affected. Supported versions 12.2.1.4.0 and 14.1.2.1.0 are affected by the flaw.
Risk and Exploitability
The CVSS base score of 7.2 suggests high severity, but the EPSS score is below 1%, meaning the probability of exploitation is currently very low. The vulnerability is not listed in CISA KEV, but the attack vector is likely through unauthenticated or weakly authenticated HTTP requests, and the attacker must possess high privileges to exploit the flaw. If exploited, the attacker could achieve full control over the Connector, potentially enabling further lateral movement within the environment.
OpenCVE Enrichment