Executive brief
Oracle Identity Manager Connector is a middleware component used to manage user identities and provisioning across enterprise systems. A high-privilege vulnerability in its Database Application Table component allows an authenticated attacker with network access to fully compromise the system, potentially gaining control over identity management operations and accessing sensitive customer data.
Technical details
The vulnerability is an exploitable flaw in the Database Application Table component of Oracle Identity Manager Connector affecting versions 12.2.1.4.0 and 14.1.2.1.0. It allows a high-privileged attacker with network access via HTTP to compromise the system without requiring user interaction or complex exploitation techniques. Successful exploitation results in complete takeover of the Oracle Identity Manager Connector, affecting confidentiality, integrity, and availability of the system. The CVSS 3.1 score of 7.2 reflects the high impact of exploitation. Patch availability and remediation steps should be obtained from Oracle's official security advisories.
Affected products
- Oracle Identity Manager Connector 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed