Executive brief
Oracle Access Manager, a tool used to manage user identities and secure access to corporate applications, contains a vulnerability in its authentication engine. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive internal data. While the attacker cannot modify data or shut down the service, this could lead to the exposure of private configuration or user information.
Technical details
A vulnerability in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware) allows for unauthorized information disclosure. The flaw is categorized as easily exploitable and can be triggered by an unauthenticated attacker via the HTTP protocol. Successful exploitation results in a loss of confidentiality, allowing the attacker to read a subset of data accessible to Oracle Access Manager. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. Security updates are typically provided via the Oracle Critical Patch Update (CPU) program.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 Critical Patch Update.