Executive brief
A critical vulnerability exists in the Oracle Identity Manager Connector, a tool used to manage user identities and access across Unix systems. A low-privileged user could exploit this flaw over the network to take full control of the connector. Because this component manages access to other systems, a successful attack could allow an intruder to compromise additional connected business applications and data.
Technical details
This vulnerability (CWE-284) exists in the Generic Unix Connector component of Oracle Identity Manager Connector. It is classified as an improper access control issue that is easily exploitable by a low-privileged attacker with network access via HTTP. The exploit does not require user interaction. A successful attack results in a 'scope change' (S:C), meaning the attacker can move beyond the Identity Manager Connector to impact other integrated products and systems. This can lead to a total compromise of confidentiality, integrity, and availability across the affected environment. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory