Impact
The flaw resides in the Authentication Engine component of Oracle Access Manager, permitting an unauthenticated attacker with network access over HTTP to gain control of the service. Successful exploitation can provide the attacker with unauthorized access to all data made available by the Access Manager, leading to a confidentiality breach while leaving integrity and availability largely untouched. The weakness is an improper access control flaw (CWE‑284).
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, both part of Oracle Fusion Middleware. No other vendors or products are mentioned in the CVE data as directly affected.
Risk and Exploitability
With a CVSS 3.1 base score of 8.6 the vulnerability is high severity, but the EPSS score of less than 1 % suggests that exploitation is currently low probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it by sending unauthenticated HTTP requests to the vulnerable Authentication Engine; because the scope changes, compromised data may also affect other Oracle applications that rely on the Access Manager service.
OpenCVE Enrichment