Impact
The vulnerability exists in the Authentication Engine of Oracle Access Manager and allows an unauthenticated attacker to access the service over HTTP. The flaw enables the attacker to bypass authentication, leading to a full takeover of the Access Manager instance. This results in total loss of confidentiality, integrity, and availability for systems relying on the compromised Access Manager. The weakness is classified under CWE‑287 (Improper Authentication) and CWE‑306 (Missing Authentication for Critical Function).
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The issue pertains to the Authentication Engine component of Oracle Fusion Middleware. Any deployment of these versions that exposes the HTTP endpoints for authentication is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a high-severity risk; the exploitation vector is network-based and requires no authentication or user interaction. The EPSS score is below 1%, suggesting that while exploitation is possible, it has not yet been widely observed, and current evidence indicates it is not part of an active exploitation campaign. The vulnerability is not listed in the CISA KEV catalog, which provides no known incident reports. However, once exploited, the attacker can fully control the Access Manager, allowing further lateral movement and privilege escalation within the network.
OpenCVE Enrichment