In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected.
https://www.oneidentity.com/community/identity-manager/
https://support.oneidentity.com/technical-documents/identity-manager/9.3/release-notes/
https://support.oneidentity.com/product-notification/noti-00001678