Impact
Oracle Access Manager’s Authentication Engine contains a flaw that enables an unauthenticated attacker with HTTP network access to compromise the service. Successful exploitation requires an attacker to initiate the request and rely on a human actor who is not the attacker to perform a completing step, after which the attacker can insert, update, or delete data that the Access Manager protects and read a subset of the data it safeguards. This results in both integrity compromise and limited confidentiality loss for affected data.
Affected Systems
The vulnerability affects Oracle Access Manager version 12.2.1.4.0 and 14.1.2.1.0. It is present in the Authentication Engine component.
Risk and Exploitability
The CVSS 3.1 base score is 6.1, indicating a moderate severity with low confidentiality (L) and integrity (L) impact. The EPSS score is below 1 %, reflecting a low probability of exploitation. It is not listed in CISA’s KEV catalog. The attack vector requires remote HTTP access, a human collaborator, and yet remains a significant threat because it can lead to unauthorized data modification and disclosure if the attack succeeds.
OpenCVE Enrichment