Impact
A flaw in the Authentication Engine component of Oracle Access Manager allows a low‑privileged attacker with network access via HTTP to compromise the system. The vulnerability can be exploited to obtain full control of the application, which in turn can affect other Oracle Fusion Middleware products due to a scope change. Successful exploitation leads to loss of confidentiality, integrity, and availability of the protected resources.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable. These are the only released releases identified as impacted by the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 8.5 indicates high severity. The EPSS score of less than 1% implies that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the theoretical impact of a successful attack—complete takeover of the Access Manager system—warrants prompt remediation. The attack vector appears to be remote over an HTTP connection, and the flaw likely involves improper access control, allowing a low‑privileged user to bypass authentication checks.
OpenCVE Enrichment