Impact
A vulnerability exists in Oracle Access Manager’s Access SDK component that can be triggered by a low‑privileged attacker who has network access via HTTP. Successful exploitation leads to a partial denial of service of the Access Manager system, impacting availability but not confidentiality or integrity. The weakness is a low‑privilege exploitable flaw with a low attack complexity and no user interaction, as reflected in its CVSS vector.
Affected Systems
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The vulnerability affects the Access SDK component of Oracle Fusion Middleware, exposing the application to HTTP requests from the network.
Risk and Exploitability
The CVSS base score of 3.1 indicates a low severity availability impact. The EPSS score is less than 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the vulnerability requires only network access and low privileges, it could be exploited by remote attackers who target servers exposed to the internet, making it potentially relevant to any organization that runs the affected versions without additional network restrictions.
OpenCVE Enrichment