Executive brief
Oracle Access Manager is a critical authentication and authorization system used by enterprises to control access to applications and data. This vulnerability allows an unauthenticated attacker to completely take over the system remotely without any user interaction, compromising all protected applications and user data managed through the platform.
Technical details
This is a critical remote code execution vulnerability in the Oracle Access Manager authentication engine affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable by an unauthenticated attacker with network access via T3 or IIOP protocols, requiring no authentication or user interaction. Successful exploitation allows complete compromise of the Oracle Access Manager system, resulting in full confidentiality, integrity, and availability impacts. Oracle has published a security update addressing this issue.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed