Impact
A flaw in the Authentication Engine of Oracle Access Manager allows a low‑privileged attacker who can reach the system over HTTP to compromise the OAM instance. This could enable configuration changes, data exfiltration and lateral movement to other Fusion Middleware products. The description states the vulnerability is "easily exploitable" and "allows takeover", so it is inferred that an attacker with network access could succeed quickly, but the exact timeline is not explicitly provided.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These releases are part of the Oracle Fusion Middleware stack and provide authentication and access control for enterprise applications.
Risk and Exploitability
The CVSS 3.1 Base Score of 9.9 indicates severe impacts on confidentiality, integrity and availability. The EPSS score of less than 1% suggests that exploitation activity is currently low. The vulnerability is remotely exploitable via HTTP with low‑privilege credentials, and the scope change noted in the description indicates that exploitation could affect additional Oracle products beyond the Access Manager itself.
OpenCVE Enrichment