Impact
An improper authentication flaw in Oracle Access Manager’s Authentication Engine allows an unauthenticated attacker who can reach the exposed HTTP interface to send specially crafted requests. The vulnerability is a classic authentication bypass (CWE‑287) that, when successfully exploited, can compromise the entire access management component, jeopardizing confidentiality, integrity, and availability of all authentication services it protects.
Affected Systems
Affected releases are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware and typically deployed in enterprise identity and access management stacks.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity. The EPSS score is less than 1%, implying an extremely low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. An attacker only needs network reach to the authentication engine’s HTTP endpoint; no credentials or privileged access are required. Successful exploitation results in full control of the Access Manager instance and potentially compromise downstream services that rely on it.
OpenCVE Enrichment