Impact
A vulnerability in the Authentication Engine component of Oracle Access Manager permits a low‑privileged attacker who can reach the server over HTTP to compromise the system. Exploitation can result in a complete takeover of Oracle Access Manager, giving the attacker full control and enabling further attacks against other products that rely on it. The impact is full compromise of confidentiality, integrity and availability.
Affected Systems
Oracle Corporation’s Oracle Access Manager, part of Oracle Fusion Middleware, is affected. Versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. No specific patch or workaround is listed by the vendor in the provided data.
Risk and Exploitability
The vulnerability has a CVSS 3.1 Base Score of 9.9, indicating critical severity. The EPSS score is less than 1 %, suggesting low but non‑zero exploitation probability. It is not yet in the CISA KEV catalog. The attack vector is inferred to be over the network via HTTP, with low privileged permissions required—a typical remote code execution scenario that can be executed from any machine with network access to the target. Successful exploitation leads to full system takeover, making the risk extremely high for any exposed instances.
OpenCVE Enrichment