Impact
The vulnerability in Oracle Access Manager, part of Oracle Fusion Middleware, permits an unauthenticated attacker to execute code over HTTP. The flaw resides in the Authentication Engine component and carries a CVSS 3.1 score of 10.0, indicating maximum impact on confidentiality, integrity, and availability. Successful exploitation can lead to full takeover of the Access Manager service, potentially affecting the overall environment.
Affected Systems
Oracle Access Manager products are affected, specifically versions 12.2.1.4.0 and 14.1.2.1.0. These versions are used in enterprise environments that rely on the Access Manager for authentication and federation services.
Risk and Exploitability
The vulnerability is highly exploitable from the network with an HTTP call, requiring no user interaction or elevated privileges. The EPSS score is under 1%, indicating a low probability of exploitation in the observed data, yet the CVSS base exposes a severe risk. The flaw is not listed in the CISA KEV catalog but has a significant scope change, meaning that once the Access Manager is compromised, other connected products may also be impacted.
OpenCVE Enrichment