Executive brief
A critical vulnerability exists in the Oracle Identity Manager Connector, a tool used to manage user identities and access across Unix systems. A low-privileged attacker can exploit this flaw over the network to take full control of the connector. Because this component manages access to other systems, a successful attack could allow the intruder to compromise additional connected products and services across the organization.
Technical details
This vulnerability is classified as Improper Privilege Management (CWE-269) within the Generic Unix Connector component of Oracle Identity Manager Connector. It is easily exploitable by a low-privileged attacker with network access via SSH. The flaw is particularly severe because it involves a 'scope change' (CVSS S:C), meaning a successful exploit allows the attacker to move beyond the security scope of the Identity Manager Connector to impact other integrated products. The vulnerability results in a total compromise of confidentiality, integrity, and availability (9.9 CVSS). Affected versions include 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Corporation Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory