Impact
The vulnerability resides in the Authentication Engine component of Oracle Access Manager. A low-privileged attacker who can reach the system over HTTPS can compromise the product. Successful exploitation would enable the attacker to create, delete, or modify access permissions and to read any data accessible through Oracle Access Manager. This grants unauthorized control over critical information and undermines both confidentiality and integrity.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. This vulnerability could also impact other Oracle Fusion Middleware products that rely on Access Manager, as the scope is listed as changed.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 9.6, indicating high severity. The EPSS score is less than 1%, suggesting that exploitation may be rare with the current public knowledge. The vulnerability is not listed in the CISA KEV catalog. The likely attack will use a network-based HTTPS request from an attacker with low privileges, targeting the Authentication Engine endpoints. Because the impact extends to confidentiality and integrity, the risk remains high even if exploitation is uncommon.
OpenCVE Enrichment