Impact
A flaw in the Authentication Engine component of Oracle Access Manager allows a low‑privileged attacker with network access via HTTP to bypass normal authentication controls. This enables unauthorized use of the system and can lead to full takeover of the Access Manager instance. The weakness is rooted in improper access control (CWE-284), resulting in complete compromise of confidentiality, integrity, and availability for the affected application.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. These releases are the only ones identified as impacted by the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 8.5 indicates high severity. The EPSS score of less than 1% implies the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, a successful exploit can result in total takeover of the Access Manager system and may affect other Oracle Fusion Middleware products due to a scope change. The attack vector is remote over an HTTP connection, requiring only low privileges, which increases the potential attack surface.
OpenCVE Enrichment