Impact
Oracle Access Manager’s Authentication Engine contains a flaw that allows an attacker with high privileges and network access via HTTP to compromise the system. The flaw can be exploited to gain full control, which leads to confidentiality, integrity, and availability violations. The CVSS 3.1 base score is 9.1, indicating a high‑severity vulnerability that can result in a complete takeover of the Access Manager service.
Affected Systems
The affected versions are Oracle Access Manager 12.2.1.4.0 and 14.1.2.1.0. The vulnerability may also impact additional Oracle Fusion Middleware components because the scope changes from the vulnerable component.
Risk and Exploitability
The EPSS score is less than 1 %, suggesting a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need network access via HTTP and high privileges to exploit the flaw. While the likelihood is low, the potential impact is catastrophic, as a successful attack could result in a full takeover of Oracle Access Manager and affect other interconnected Fusion Middleware components due to the noted scope change.
OpenCVE Enrichment