Impact
The vulnerability is in the Authentication Engine component of Oracle Access Manager and allows an attacker with low privileges and network access via HTTP to compromise the product. An attacker can create, delete, or modify access permissions, gain unauthorized access to critical data, and cause a partial denial of service. The flaw thus leads to high confidentiality and integrity impact and can also affect availability to a limited extent.
Affected Systems
Oracle Access Manager by Oracle Corporation, versions 12.2.1.4.0 and 14.1.2.1.0, are affected. The vulnerability may also impact other Oracle Fusion Middleware components because the authentication engine is used across services, potentially changing the scope of the compromise.
Risk and Exploitability
CVSS base score of 9.9 classifies the issue as critical. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not yet listed in CISA KEV. However, the remote attack vector over HTTP and the requirement of only low privileges make it attractive to attackers. The flaw’s impact includes unauthorized data access, potential manipulation of access controls, and partial service disruption, which collectively pose a severe risk to systems relying on Oracle Access Manager.
OpenCVE Enrichment