The CVSS 9.9 assigned to this Oracle Identity Manager vulnerability demands immediate scrutiny against the empirical signal: an EPSS score of 0.00447 indicates roughly 4 in 1,000 exploitation attempts will succeed within 30 days. The disconnect between the headline severity and the low probability metric is not a scoring anomaly — it is a structural feature of how vendor-supplied exploitability language interacts with CVSS 3.1's scoring engine. Oracle describes this as 'easily exploitable' with 'low privilege' access, yet these claims have not translated into observed exploit activity. The EPSS aggregates against this disclosure: automated systems have already processed the exploit availability, patch maturity, and network accessibility factors, and they assign low probability. What the 9.9 score captures is vendor disclosure behavior, not attacker behavior. The 'scope change' language in the vector — indicating attacks may impact additional components — warrants careful interpretation in the IAM context. Oracle Identity Manager functions as an identity broker to downstream systems by design; compromising it provides direct access to federated resources without requiring a second vulnerability. This is not a scoring artifact but an architectural reality. However, historical pattern analysis of Oracle IAM vulnerabilities reveals a consistent lineage: high CVSS scores, frequent scope change language, and vanishingly rare appearances in actual exploitation toolkit discussions or incident post-mortems. The theoretical blast radius exists; the practical realization of that blast radius has not materialized in the documented genealogy of these vulnerabilities. The 'Legacy UI' component qualifier is the most operationally significant detail in this disclosure. This denotes deprecated code — a path being phased out, likely with orphaned security controls, inconsistent authentication enforcement compared to the current interface, and reduced monitoring coverage. Generic exploit infrastructure does not target this specific legacy endpoint, which explains the low EPSS. That same EPSS cannot measure targeted reconnaissance by an actor who knows the old UI exists and understands its different security posture. Organizations running OIM should treat this as a blast radius problem, not a pure probability problem. The 9.9 does not reliably translate to exploitation likelihood, but if compromise occurs, the downstream impact is architectural and severe. Prioritize compensating controls: isolate OIM from non-essential network paths, enforce strict authentication on legacy interfaces specifically, and audit trust relationships to downstream systems. The temporal risk profile matters — a 9.9 that sits unpatched while being deprioritized due to low EPSS accumulates debt as compensating controls degrade over time.