Executive brief
A vulnerability exists in the Oracle Identity Manager Connector, a tool used to synchronize user identity data between Oracle and Unix systems. An attacker with access to the same local network segment could potentially modify or delete critical identity data or cause the service to crash. This could lead to unauthorized access changes across the organization or a total disruption of identity management services.
Technical details
This vulnerability affects the Generic Unix Connector component of Oracle Identity Manager Connector. It is classified as difficult to exploit (AC:H) and requires the attacker to be on the same physical or logical network segment (AV:A) as the target hardware. An unauthenticated attacker can exploit this flaw to gain unauthorized creation, deletion, or modification access to all data accessible by the connector. Additionally, the exploit can trigger a hang or repeatable crash, resulting in a complete denial of service. The vulnerability includes a scope change (S:C), meaning the impact can extend beyond the connector itself to other integrated products. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published