Impact
The flaw resides in the Authentication Engine of Oracle Access Manager, enabling a low‑privileged attacker with network access to supply crafted HTTP requests that bypass authentication and authorization controls. Successful exploitation allows the attacker to gain full control over the application, compromising confidentiality, integrity, and availability of all data processed by the product. The described scope change indicates that the impact may extend beyond Oracle Access Manager to other components of Oracle Fusion Middleware that are part of the same deployment.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. Both major branches carry the vulnerability, and the issue can also influence related Oracle Fusion Middleware components due to the scope change noted in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 9.9 signals a critical risk. An EPSS score of less than 1% suggests the current probability of exploitation is low, yet the vulnerability is publicly documented and could be leveraged by an attacker. The likely attack vector is remote HTTP traffic, and the flaw requires only low‑privilege network access to launch an effective compromise.
OpenCVE Enrichment