Impact
A vulnerability in the Authentication Engine component of Oracle Access Manager permits an attacker with limited privileges who can reach the system via HTTP to compromise the service. Successful exploitation can lead to full control of the Access Manager, resulting in loss of confidentiality, integrity, and availability of the authentication infrastructure. The description indicates that normal credential checks may be bypassed; however, this inference is not explicitly confirmed in the provided data.
Affected Systems
The issue affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. Any environment deploying either of these releases is vulnerable unless mitigated or patched.
Risk and Exploitability
A CVSS v3.1 score of 8.8 reflects high severity, and the entry is not listed in CISA's KEV catalog. The EPSS score is < 1%, but the vulnerability description indicates that it is easily exploitable over the network via HTTP. Given the low attack effort and the potential for a complete service takeover, the risk should be treated as high.
OpenCVE Enrichment