Impact
Oracle Access Manager’s Authentication Engine suffers a vulnerability that, if exploited, allows an attacker who only has network traffic capability to the HTTP interface to bypass all authentication controls and perform unauthorized create, delete, or modify operations on any data accessible through the platform. The flaw directly affects the confidentiality and integrity of critical data, as it permits full manipulation of the system’s data store.
Affected Systems
The affected products are Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware. Any installation of these product releases that has not been updated with the vendor’s latest security patches is vulnerable.
Risk and Exploitability
This vulnerability carries a CVSS‑3.1 score of 9.1 (high to critical). The attack vector is network‑only over HTTP, with low complexity and no privilege or user interaction required. The EPSS score is below 1 % indicating a very low probability of exploitation in the current environment, and the flaw is not listed in the CISA KEV catalog. Additional risk is increased if the Access Manager HTTP interface remains exposed to untrusted networks.
OpenCVE Enrichment