Impact
The flaw in the Authentication Engine of Oracle Access Manager enables an unauthenticated user to issue a crafted HTTP request that bypasses the authentication process (CWE‑287). This bypass grants the attacker unauthorized access to data that should be protected by the Access Manager. The vulnerability can be triggered over the network without any prior authentication or privileges, exposing sensitive information to the attacker.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The issue is documented in Oracle Fusion Middleware and may impact other products that rely on the Access Manager when integrated, potentially broadening the attack surface across a deployment.
Risk and Exploitability
The CVSS 3.1 base score of 8.6 indicates a high severity vulnerability that can be exploited remotely over the network and requires minimal effort. The EPSS score of less than 1% suggests current exploitation is unlikely, though the vulnerability remains unlisted in CISA KEV. The scope extends beyond the Access Manager, potentially granting full access to other integrated applications, in line with the authentication bypass described by CWE‑287.
OpenCVE Enrichment