Executive brief
Oracle Identity Manager Connector is a critical component of Oracle Fusion Middleware used to manage identity and access controls across enterprise systems. A network-accessible vulnerability allows unauthenticated attackers to bypass security controls and gain unauthorized access to create, modify, or delete sensitive identity data, potentially compromising the integrity of identity management across dependent systems and applications.
Technical details
This is an authentication bypass vulnerability in the Core component of Oracle Identity Manager Connector that allows unauthenticated remote attackers with network access via TCP to compromise the system. The vulnerability has difficult exploit complexity but enables attackers to achieve unauthorized creation, deletion, and modification of critical identity data, as well as complete read access to all accessible data. The scope is marked as changed, meaning successful exploitation can impact additional Oracle products that depend on Identity Manager Connector. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed