Impact
An improper authorization weakness in Oracle Access Manager’s Authorization Engine permits a local or remote attacker with low‑privileged credentials to send specially crafted TCP requests that exhaust resources or otherwise render the component unavailable. The vulnerability is exploitable without user interaction and provides direct damage to availability, as reflected in the CVSS v3.1 score of 4.3 and the single impact category of availability.
Affected Systems
The flaw affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, both delivered as part of Oracle Fusion Middleware.
Risk and Exploitability
The EPSS score of less than 1% indicates that the vulnerability has a very low probability of being seen in the wild, and it is not listed in CISA's KEV catalog. Nevertheless, the remote attack vector and the lack of required user interaction make it straightforward for an attacker who can reach the exposed ports. Because the attack can result in a partial denial of service, it is recommended that the vulnerability be treated with the same priority as any other availability issue.
OpenCVE Enrichment