Executive brief
Oracle Identity Manager Connector is a component of Oracle Fusion Middleware used to manage user identities and access across enterprise systems. A privilege escalation vulnerability in this product allows a user with basic local access to the server to gain complete control over the connector, potentially compromising all identity and access management functions it governs. This could result in unauthorized access to accounts and systems managed by the connector.
Technical details
This local privilege escalation vulnerability in the Oracle Identity Manager Connector core component affects versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability requires low-level user privileges and local logon access to the infrastructure where the connector is installed; no network vector or user interaction is needed once local access is obtained. A successful exploit allows an attacker to achieve complete compromise of the Oracle Identity Manager Connector process, resulting in full confidentiality, integrity, and availability impact. The vulnerability has a CVSS 3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating a high-severity local exploit with low complexity.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed