Impact
A flaw in the Oracle Access Manager Authentication Engine allows an attacker with low local privileges and access to the physical network segment that the hardware runs on to compromise the product. The vulnerability exploits a weakness in authentication (CWE‑287). Successful exploitation can result in a complete takeover of Oracle Access Manager, with severe confidentiality, integrity, and availability impacts at score 8.0.
Affected Systems
The affected products are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware. Systems running these versions are at risk if a low‑privileged attacker can connect to the same local network segment as the Oracle Access Manager hardware.
Risk and Exploitability
The CVSS score of 8.0 and an EPSS score of <1% suggest that overall exploitation likelihood is low, yet the vector AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates that the flaw can be exploited from a local network with minimal privileges and no user interaction. It is not listed in CISA KEV. The likely attack vector is a low‑privileged attacker on the same physical network who can reach the Oracle Access Manager instance. Successful exploitation would result in a takeover of Oracle Access Manager.
OpenCVE Enrichment