Executive brief
Oracle Access Manager, a tool used to manage user identities and secure access to corporate applications, contains a security flaw in its authentication engine. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive data. This could lead to unauthorized access to corporate systems and potential data tampering.
Technical details
An improper access control vulnerability (CWE-284) exists in the Authentication Engine component of Oracle Access Manager. The flaw is remotely exploitable via HTTP without authentication, though it requires interaction from a victim (User Interaction: Required). Due to a scope change (Scope: Changed), an exploit can impact additional products beyond the primary Access Manager instance. Attackers can achieve unauthorized read, update, insert, or delete access to a subset of data. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Security Alert published