Impact
This vulnerability exists in the Authentication Engine component of Oracle Access Manager and allows an unauthenticated attacker that can reach the service over HTTP to compromise the system. An attacker can achieve full system takeover, compromising confidentiality, integrity, and availability. The flaw reflects an improper access control issue (CWE-284) that permits bypass of authentication checks.
Affected Systems
Affected vendors/products: Oracle Corporation's Oracle Access Manager as part of Oracle Fusion Middleware. Supported releases 12.2.1.4.0 and 14.1.2.0.0 are affected. No other versions were identified at the time of this advisory.
Risk and Exploitability
The CVSS v3.1 base score severe impact, yet the EPSS score of less than 1 % indicates a low probability of widespread exploitation. The vulnerability is not yet catalogued in the CISA KEV listing. Exploitation would require the attacker to successfully reach the authentication engine via the public HTTP interface without valid credentials, then exploit the access control flaw to gain administrative control. Because the attack path is relatively simple and the damage is total takeover, the threat remains significant for exposed installations.
OpenCVE Enrichment