Impact
The flaw is an improper access control vulnerability in Oracle Access Manager’s Authentication Engine. It allows an attacker who can reach the system over HTTP to create, delete, or modify access rights, effectively granting unauthorized control over sensitive data held within the product. The vulnerability’s impact is significant to confidentiality and integrity, as noted by the CVSS vector that includes both high confidentiality and integrity impacts.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 issued by Oracle Corporation are affected. The flaw may also influence other Oracle Fusion Middleware components that rely on Access Manager, expanding the potential damage beyond the immediate product.
Risk and Exploitability
The CVSS score of 8.7 classifies the weakness as high severity. Although the EPSS indicates a low probability (< 1%), the vulnerability is considered easily exploitable to a high‑privileged attacker with network access via HTTP. The impact scope extends beyond a single component, enabling attackers to alter or delete access controls across the system. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment