Description
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: High-Privilege Takeover
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware allows a high privileged attacker with network access via HTTP to compromise the application, resulting in confidentiality, integrity and availability loss. The flaw is described as easily exploitable and is capable of leading to full takeover of the Connector. The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, indicating a significant risk to all security properties.

Affected Systems

Oracle Corporation’s Oracle Identity Manager Connector is affected. Supported versions 12.2.1.4.0 and 14.1.2.1.0 are affected by the flaw.

Risk and Exploitability

The CVSS base score of 7.2 suggests high severity, but the EPSS score is below 1%, meaning the probability of exploitation is currently very low. The vulnerability is not listed in CISA KEV, but the attack vector is likely through unauthenticated or weakly authenticated HTTP requests, and the attacker must possess high privileges to exploit the flaw. If exploited, the attacker could achieve full control over the Connector, potentially enabling further lateral movement within the environment.

Generated by OpenCVE AI on September 20, 2026 at 07:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the Oracle security patch for the Oracle Identity Manager Connector as detailed in Oracle’s security alert for CVE-2026-83344.
  • Restrict external HTTP access to the Connector by applying network segmentation or firewall rules, allowing only trusted administrative hosts.
  • Continuously monitor Connector logs and network traffic for suspicious activity and conduct regular vulnerability scans to detect any new exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 07:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Oracle Identity Manager Connector High Privilege Network Exploit

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via HTTP in Oracle Identity Manager Connector
Weaknesses CWE-284
CWE-287

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via HTTP in Oracle Identity Manager Connector
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle identity Manager Connector
CPEs cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle identity Manager Connector
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Identity Manager Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:25.683Z

Reserved: 2026-08-31T15:40:57.354Z

Link: CVE-2026-83344

cve-icon Vulnrichment

Updated: 2026-09-17T12:59:22.349Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:47.800

Modified: 2026-09-17T14:17:42.623

Link: CVE-2026-83344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management