Impact
The Authentication Engine component of Oracle Access Manager has a flaw that allows an unauthenticated attacker with network access over HTTP to compromise the entire service. The vulnerability, classified as CWE-306, provides the attacker with full control of the system, thereby producing a confidentiality, integrity, and availability breach. The high CVSS 3.1 score of 9.8 reflects the severity of this single point of failure.
Affected Systems
Versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Access Manager are affected. These releases belong to Oracle Fusion Middleware and are commonly used to centralize authentication for multiple applications and services. Systems running either of these versions are vulnerable when exposed to public or internal networks that can reach the application over HTTP.
Risk and Exploitability
The vulnerability allows exploitation without authentication, requiring only network connectivity via standard HTTP. The EPSS score of less than one percent indicates a low expectation of widespread attacks to date, but the lack of any known exploitation in the CISA KEV catalog and the critical nature of the impact keep risk high. An attacker who can reach the exposed service can take over the Access Manager deployment, potentially gaining access to all integrated applications and data.
OpenCVE Enrichment