Impact
An authentication bypass flaw exists in the Authentication Engine component of Oracle Access Manager. The flaw originates from insufficient authentication checks, allowing an unauthenticated attacker to access administrative functions via HTTP. Successful exploitation permits a complete takeover of the Access Manager instance, compromising confidentiality, integrity, and availability of the authentication service. The vulnerability is rooted in CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication).
Affected Systems
Oracle Access Manager version 12.2.1.4.0 and 14.1.2.1.0 in Oracle Fusion Middleware are affected. Systems running these releases with the Authentication Engine exposed over HTTP are vulnerable; the flaw resides in the authentication engine component typically deployed behind a web tier.
Risk and Exploitability
The CVSS v3.1 score of 9.8 indicates extreme severity, with a high likelihood of exploitation even though the EPSS score is below 1%, implying that currently exploit code may not be broadly available but the vulnerability remains highly valuable to actors. The vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) shows network access as the sole attack vector, no privileges required, and no user interaction needed. The flaw is not yet listed in CISA KEV, yet its potential to compromise the entire authentication infrastructure makes it a critical priority for immediate action.
OpenCVE Enrichment