Executive brief
Oracle Identity Manager Connector is a credential and identity management component within Oracle Fusion Middleware used to synchronize user identities and access across enterprise systems. A flaw allows an attacker with physical access to the network segment where the connector runs to bypass authentication controls and fully compromise the system, potentially exposing or modifying identity data for all connected applications.
Technical details
A difficult-to-exploit vulnerability in the Core component of Oracle Identity Manager Connector (versions 12.2.1.4.0 and 14.1.2.1.0) allows an unauthenticated attacker with adjacent network access to compromise the system. The vulnerability enables full takeover of the connector, impacting confidentiality, integrity, and availability. The attack vector is adjacent (physical network segment access required) with high complexity; no user interaction or authentication is needed. No official fix details are available from the provided advisory text.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed