ZeroHour

CVE-2026-83344

moderate

High-Privilege Takeover in Oracle Identity Manager Database App Tables Connector

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

Oracle Identity Manager Connector (Fusion Middleware), specifically the Database Application Tables component, contains an easily exploitable vulnerability in versions 12.2.1.4.0 and 14.1.2.1.0 that allows a high-privileged attacker with network access via HTTP to fully take over the connector. Exploitation requires valid high-privileged credentials — think a malicious or compromised administrator account rather than an anonymous outsider — but once those privileges are held, the attack is low-complexity, needs no user interaction, and compromises confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). Because OIM connectors handle identity provisioning and reconciliation, a connector takeover could let the attacker manipulate identity data flowing between Oracle Identity Manager and connected database applications. Organizations running either affected version of the Database Application Tables connector are exposed, particularly those that allow HTTP access to connector endpoints from broader networks. No public proof-of-concept exists, the flaw is not on CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediated this flaw to the Database Application Tables connector on both 12.2.1.4.0 and 14.1.2.1.0 deployments. Restrict HTTP access to OIM and connector endpoints to trusted administration networks, and audit high-privileged accounts and recent connector configuration changes for signs of abuse. Review Oracle's Critical Patch Update advisory for the definitive patch numbers and any documented workarounds.

Affected
Oracle Identity Manager Connector (Database Application Tables component, Oracle Fusion Middleware)
Estimated exposure
moderatelikely low thousands of enterprise deployments worldwide (order of ~1,000–10,000 connector instances) — Oracle Identity Manager is an enterprise identity-governance suite deployed on-premises mainly in large organizations, and the Database Application Tables connector is an optional per-deployment component, so exposure is bounded by that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.