An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
https://github.com/Live-Hack-CVE/CVE-2022-25626
https://support.broadcom.com/external/content/SecurityAdvisories/0/21136