Impact
The Oracle Access Manager Authentication Engine contains a flaw that allows an unauthenticated attacker with network access over HTTP to bypass authentication or impersonate users, resulting in a full takeover of the OAAM instance. This weakness directly impacts confidentiality, integrity, and availability of the system and any associated resources. The flaw is cataloged as CWE‑287: Improper Authentication.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 9.8, classifying it as critical. EPSS indicates a less than 1% chance of exploitation at this time, and it is not listed in CISA’s KEV catalog. The likely attack vector is inferred to be an unauthenticated HTTP request to exposed authentication endpoints, requiring only network connectivity to the affected OAAM instance.
OpenCVE Enrichment