Impact
Oracle Access Manager’s Authentication Engine contains a broken access control flaw (CWE-284) that enables an attacker who has high‑privilege credentials and network access over HTTP to gain full administrative control. Successful exploitation can result in a complete takeover of the component, allowing arbitrary configuration changes, data exfiltration, and service disruption. The formal description notes that such compromise would impact confidentiality, integrity, and availability of the system.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The reported scope change indicates that compromise of the Authentication Engine may extend to other Oracle Fusion Middleware products in the environment. No other versions are explicitly listed as affected in the advisory.
Risk and Exploitability
The CVSS base score of 9.1 marks this vulnerability as critical. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in CISA KEV. The advisory describes it as easily exploitable and notes that an attacker needs network access to the HTTP interface and high‑privilege privileges to successfully exploit it.
OpenCVE Enrichment