Executive brief
A critical vulnerability exists in the Oracle Identity Manager Connector, a tool used to manage user identities and access across enterprise databases. A low-privileged user could exploit this flaw over the network to take full control of the connector. This could lead to unauthorized access to sensitive corporate data, disruption of identity management services, and potential lateral movement to other connected systems.
Technical details
This vulnerability is classified as Improper Access Control (CWE-284) within the Database User component of Oracle Identity Manager Connector. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw is particularly severe because it involves a 'scope change' (CVSS Score 9.9), meaning a successful exploit allows the attacker to move beyond the security scope of the connector itself to impact other parts of the Oracle Fusion Middleware environment. Successful exploitation results in a complete takeover of the Identity Manager Connector, compromising confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Security Alert published