Impact
Oracle Access Manager’s Authentication Engine contains a broken access control flaw (CWE-284) that permits an attacker with network reachability over HTTP to gain full administrative control. The vulnerability enables a high‑privileged attacker to fully compromise the component, allowing arbitrary configuration changes, data exfiltration, and service disruption. The formal description states that successful exploitation can result in a complete takeover of Oracle Access Manager, exposing confidential data and impacting the confidentiality, integrity, and availability of the system.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. No other versions are affected according to the advisory, and upgrades beyond these releases include the fix. The flaw’s scope change indicates that compromise of the Authentication Engine could also affect other Oracle Fusion Middleware products in the environment.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 categorizes this as a critical vulnerability. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the flaw is not currently listed in CISA’s KEV catalog. Nevertheless, the advisory labels it as easily exploitable, implying minimal preparation is required. Attackers would need network access to the HTTP interface and high‑privilege credentials or the ability to forge them, after which they can gain full control of the Authentication Engine and potentially affect other connected components.
OpenCVE Enrichment