Impact
A flaw in the Authentication Engine of Oracle Access Manager allows an attacker who can reach the application over HTTP to gain unauthorized access without credentials. The vulnerability permits acquisition of all data that the Access Manager can expose, potentially giving control over authentication services and sensitive information. The weakness is categorized as Improper Access Control.
Affected Systems
Oracle Access Manager product versions 12.2.1.4.0 and 14.1.2.1.0 are affected; any deployment of these versions is subject to the flaw.
Risk and Exploitability
The CVSS 3.1 base score of 8.6 and a Scope Change indicate a high‑impact, cross‑component compromise. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalogue. An unauthenticated attacker with network access via HTTP can exploit the flaw, gaining unrestricted access to critical data and potentially affecting other connected products.
OpenCVE Enrichment