Executive brief
Oracle Access Manager is a security product used to control access to enterprise applications and services. A low-privileged attacker with network access can exploit a flaw in the authorization engine to cause a partial service outage, affecting the availability of the access management system for legitimate users.
Technical details
This is an availability vulnerability in the Authorization Engine component of Oracle Access Manager. The vulnerability is easily exploitable and requires only low-level privileges and network access over TCP; no authentication bypass or authentication is explicitly required beyond the attacker's existing low-privileged status. Successful exploitation results in a partial denial of service (partial DOS) of Oracle Access Manager, impacting service availability. The flaw affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. Patches are expected to be available through Oracle's security update channels.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-08-18: disclosed