Impact
Oracle Access Manager contains a flaw that allows an unauthenticated attacker with network access to the SAML interface to send crafted SAML requests, bypassing authentication and gaining full control of the system. The attacker can read, modify, or delete any data protected by Access Manager and may use the compromise to attack downstream applications. This improper access control flaw (CWE-287) results in confidentiality, integrity, and availability impacts.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 within Oracle Fusion Middleware are affected. Systems running these versions without the recent security update are vulnerable to unauthenticated takeover via the SAML endpoint.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 9.8, indicating critical severity. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, but the flaw is easily exploitable by an unauthenticated attacker with network access via the SAML interface. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network‑based attack through the SAML endpoint, requiring no authentication and only the ability to send SAML packets.
OpenCVE Enrichment