Impact
A flaw in the Authentication Engine of Oracle Access Manager allows an attacker with low privilege on the same physical communication segment as the device to override authentication and seize control of the service. This vulnerability can compromise confidentiality, integrity, and availability of identity data and other critical functions. The weakness is identified as an improper access control (CWE‑284) and results in a full takeover of the application when successfully exploited.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware, are affected. These releases provide authentication handling for enterprise environments.
Risk and Exploitability
The base CVSS score is 8.0 with an adjacent network access vector, low attack complexity, low privilege required, and no user interaction. The EPSS score is below 1 % indicating a low yet non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers must have physical or near‑physical proximity to the hardware running Oracle Access Manager to exploit the flaw, allowing local attackers to gain full control of the service without additional elevated permissions.
OpenCVE Enrichment