Executive brief
Oracle Identity Manager Connector is a core component of Oracle Fusion Middleware that manages identity and access control. An attacker with physical access to the network segment where this connector is deployed can compromise it without authentication, potentially gaining complete control over identity management systems and affecting downstream applications that depend on it.
Technical details
This is a difficult-to-exploit vulnerability requiring physical access to the communication segment (adjacent network proximity). The vulnerability affects the Core component of Oracle Identity Manager Connector and allows unauthenticated attackers to achieve complete compromise. No user interaction is required. The scope is marked as changed, meaning successful exploitation can impact other products beyond the connector itself. Affected versions are 12.2.1.4.0 and 14.1.2.1.0. Patch availability through Oracle's security updates is expected.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed