Impact
Vulnerability in Oracle Access Manager’s Authentication Engine allows a low‑privileged attacker who can reach the system over HTTP to compromise the component. exploited, results in a full takeover of Oracle Access Manager, compromising confidentiality, integrity, and availability. The weakness matches the class of authentication bypass vulnerabilities (CWE‑287).
Affected Systems
Oracle Access Manager 14.1.2.1.0 from Oracle Corporation. No other versions are reported as affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity with critical confidentiality, integrity, and availability impacts. The EPSS score of less than 1% suggests that, although the vulnerability is theoretically exploitable, the current probability of real‑world exploitation is very low. The item is not listed in CISA’s KEV catalog. Exploitation requires network access to the HTTP interface of the Authentication Engine and only a low‑privileged user context, so a malicious actor could leverage existing network connectivity to attack the vulnerable instance without high‑level credentials.
OpenCVE Enrichment