Executive brief
Oracle Access Manager is a centralized authentication and authorization system used to protect enterprise applications and secure network access. A vulnerability in its Authentication Engine allows attackers with low-level network access to bypass authentication controls, potentially exposing sensitive data or enabling unauthorized modifications across multiple connected systems. This vulnerability affects critical versions of the product and could significantly impact business operations and customer data security.
Technical details
The vulnerability exists in the Authentication Engine component of Oracle Access Manager and allows authentication bypass via the HTTPS protocol. A low-privileged attacker with network access can exploit this flaw without requiring user interaction. Successful exploitation results in unauthorized creation, deletion, or modification of critical data within Oracle Access Manager, and may extend to unauthorized access across other products that depend on Access Manager for authentication. The vulnerability has a scope change (C:H, I:H, A:N), indicating impacts beyond the directly affected component. Patching is necessary for versions 12.2.1.4.0 and 14.1.2.1.0.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed