Executive brief
Oracle Access Manager is a centralized authentication and authorization system used by enterprises to control access to applications and data. An unauthenticated attacker can exploit this vulnerability via the network to gain unauthorized access to sensitive data stored within Oracle Access Manager and potentially other connected systems. The flaw allows attackers to bypass authentication controls without requiring credentials or user interaction, posing a critical risk to customer data confidentiality.
Technical details
This is an authentication bypass vulnerability in the Authentication Engine component of Oracle Access Manager, affecting versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is easily exploitable over the network via HTTP without requiring authentication or user interaction (network-accessible, no auth required). An unauthenticated attacker can achieve unauthorized access to critical data managed by Oracle Access Manager and potentially data from other integrated systems due to the scope change. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H) indicates a high-impact confidentiality breach with changed scope affecting other components.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed