Junglewise Threat Intelligence

CVE-2021-35587: Oracle Fusion Middleware Unspecified Vulnerability

CVE-2021-35587 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-11-28

Technologies: Oracle Access Manager, Oracle Fusion Middleware. Vendors: Oracle.

Executive brief

A vulnerability in the OpenSSO Agent component of Oracle Access Manager allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation can lead to a complete takeover of the Oracle Access Manager product.

Affected products

  • Oracle Access Manager 11.1.2.3.0, 12.2.1.3.0, 12.2.1.4.0

Timeline

  • 2022-01-19: disclosed: NVD Published Date
  • 2022-01-19: advisory: Oracle Critical Patch Update Advisory - January 2022
  • 2022-11-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-11-28: exploited: Reported as exploited in the wild per CISA KEV entry date.

Related threats