Executive brief
A vulnerability exists in the Oracle Access Manager Web Server Plugin, a component used to manage user authentication and secure access to enterprise applications. An unauthenticated attacker could exploit this over the network to view, modify, or delete sensitive identity data, or disrupt the availability of the authentication service. This could lead to unauthorized data changes or a partial service outage for users attempting to log in.
Technical details
An improper access control vulnerability (CWE-284) exists in the Web Server Plugin component of Oracle Access Manager. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of data accessible to the manager and can result in a partial denial of service (DoS). Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory