Impact
This vulnerability is an authentication bypass that allows an unauthenticated attacker to compromise Oracle Access Manager. The weakness, identified as CWE‑287 and CWE‑306, permits attackers to gain full control of the system, providing the attacker with confidentiality, integrity, and availability impacts. Successful exploitation can lead to complete takeover of the Oracle Access Manager instance and the data it protects.
Affected Systems
Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware. Only these releases are affected; other versions are not impacted.
Risk and Exploitability
The vulnerability scores a CVSS 3.1 base score of 9.8, indicating a critical risk. The EPSS score is less than 1 percent, suggesting a low current exploitation probability, but the absence of the vulnerability from the CISA KEV catalog does not reduce its severity. Attackers can exploit it remotely over network protocols T3 and IIOP, requiring no authentication. Given the high severity and the possibility of remote compromise, the risk is significant for vulnerable environments.
OpenCVE Enrichment