Impact
The vulnerability resides in Oracle Identity Manager’s legacy UI and permits an unauthenticated attacker accessing the web interface over HTTP to create, modify, or delete data that the Identity Manager manages. The flaw requires human interaction from a third party to complete the exploit but does not grant full system compromise or code execution. The impact is a loss of confidentiality and integrity for critical data, as an attacker can alter or delete records stored in Oracle Identity Manager.
Affected Systems
Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 are affected.
Risk and Exploitability
The CVSS 3.1 base score is 8.1, with an access vector of network and no privileges required, user interaction required, and a high impact on confidentiality and integrity. The EPSS score is less than 1 %, indicating a low probability of exploitation at the time of analysis. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker can exploit the flaw by sending crafted requests to the web service from any system that can reach the Identity Manager’s HTTP port, but the presence of a human interaction step reduces the likelihood of automated attacks.
OpenCVE Enrichment