Impact
Oracle Access Manager has an authentication engine flaw that permits an unauthenticated attacker with HTTP network access to compromise the application, potentially allowing full access to all data exposed through Oracle Access Manager. The weakness is an authentication bypass, consistent with CWE‑306, which directly impacts confidentiality, with no integrity or availability impact noted.
Affected Systems
The vulnerability affects Oracle Access Manager, specifically versions 12.2.1.4.0 and 14.1.2.1.0. Because the scope is marked as Changed, other Oracle Fusion Middleware components that interact with Oracle Access Manager may also be impacted.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.6 indicates high severity, and the EPSS score of less than 1% shows that exploitation is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog. An attacker with network access can trigger the flaw by sending crafted HTTP requests to the Authentication Engine without any authentication or UI interaction, achieving unauthorized access to sensitive data. The overall risk is high severity but low probability of exploitation as of the current EPSS value.
OpenCVE Enrichment