Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-09-15
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Partial denial of service
Action: Mitigate
AI Analysis

Impact

A vulnerability exists in Oracle Access Manager’s Access SDK component that can be triggered by a low‑privileged attacker who has network access via HTTP. Successful exploitation leads to a partial denial of service of the Access Manager system, impacting availability but not confidentiality or integrity. The weakness is a low‑privilege exploitable flaw with a low attack complexity and no user interaction, as reflected in its CVSS vector.

Affected Systems

Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The vulnerability affects the Access SDK component of Oracle Fusion Middleware, exposing the application to HTTP requests from the network.

Risk and Exploitability

The CVSS base score of 3.1 indicates a low severity availability impact. The EPSS score is less than 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the vulnerability requires only network access and low privileges, it could be exploited by remote attackers who target servers exposed to the internet, making it potentially relevant to any organization that runs the affected versions without additional network restrictions.

Generated by OpenCVE AI on September 18, 2026 at 18:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • If a patch is not available or cannot be applied immediately, restrict HTTP access to the Access Manager servers using firewall rules or VPNs so only trusted internal hosts can reach the service
  • Review configuration settings on the Access Manager to disable or limit features that allow remote requests from untrusted clients
  • Monitor the system for repeated failed or unusual requests that may indicate an attempted exploitation

Generated by OpenCVE AI on September 18, 2026 at 18:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Partial Denial-of-Service via HTTP in Oracle Access Manager Access SDK
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle access Manager
CPEs cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle access Manager
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Access Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T16:14:43.061Z

Reserved: 2026-08-31T15:40:57.355Z

Link: CVE-2026-83369

cve-icon Vulnrichment

Updated: 2026-09-18T16:11:51.304Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:49.243

Modified: 2026-09-21T18:06:37.013

Link: CVE-2026-83369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:15:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption