Impact
Oracle Access Manager’s Authentication Engine contains a flaw that allows an attacker with high privileges and network access via HTTP to compromise the system. The flaw can be exploited to gain full control, which leads to confidentiality, integrity, and availability violations. The CVSS 3.1 base score is 9.1, indicating a high‑severity vulnerability that can result in a complete takeover of the Access Manager service.
Affected Systems
The affected versions are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0. The vulnerability may also impact additional Oracle Fusion Middleware components because the scope changes from the vulnerable component.
Risk and Exploitability
The EPSS score is less than 1 %, indicating a low probability of exploitation, and the issue is not listed in CISA’s KE is network‑based over HTTP and requires high privileges, the overall risk is moderate but the potential impact is catastrophic if the vulnerability is exploited. Successful service, leading to potential exploitation of other connected systems due to the reported scope change.
OpenCVE Enrichment