Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Identity Manager Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized read access to a subset of Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N).
CVE-2026-34294 is a vulnerability in Oracle Identity Manager Connector affecting version 12.2.1.4.0 that allows low-privileged attackers with network access via LDAP to compromise the system. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data and unauthorized read access to sensitive information.
ثغرة في مكون Microsoft Active Directory بموصل Oracle Identity Manager تسمح لمهاجمين بامتيازات منخفضة بالوصول عبر LDAP. يمكن للمهاجمين إنشاء أو حذف أو تعديل البيانات الحرجة والوصول غير المصرح به إلى المعلومات الحساسة. الثغرة تتطلب مستوى صعوبة عالي للاستغلال لكنها تؤثر على سرية وسلامة البيانات.
This vulnerability affects Oracle Identity Manager Connector version 12.2.1.4.0, allowing low-privileged network attackers to exploit the Microsoft Active Directory component via LDAP. Attackers can gain unauthorized access to create, delete, or modify critical data and read sensitive information.
Upgrade Oracle Identity Manager Connector to the latest patched version beyond 12.2.1.4.0. Implement network segmentation to restrict LDAP access to authorized systems only. Apply principle of least privilege for user accounts accessing the connector. Monitor LDAP authentication logs for suspicious activities and implement strong authentication mechanisms.
قم بترقية موصل Oracle Identity Manager إلى أحدث إصدار مصحح بعد 12.2.1.4.0. طبق تقسيم الشبكة لتقييد الوصول إلى LDAP للأنظمة المصرح بها فقط. طبق مبدأ الامتيازات الأقل للحسابات التي تصل إلى الموصل. راقب سجلات مصادقة LDAP للأنشطة المريبة وطبق آليات مصادقة قوية.