Executive brief
Oracle Identity Manager Connector is a component of Oracle Fusion Middleware used to manage user identity and access across enterprise systems. A vulnerability in the connector allows an attacker with physical access to the network segment where the connector runs to bypass authentication and gain unauthorized access to critical identity data, potentially compromising the entire identity management infrastructure and all connected systems.
Technical details
This vulnerability in Oracle Identity Manager Connector (Core component) allows unauthenticated attackers with network access to the physical communication segment to compromise the connector. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. Successful exploitation enables unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data managed by the connector. The attack vector is adjacent (physical network segment), requires no authentication or user interaction, and has scope change, meaning impacts extend beyond the vulnerable component to other Oracle systems. A CVSS v3.1 score of 9.3 reflects the high confidentiality and integrity impacts.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed