CRITICAL

CVE-2021-35587

Oracle Access Manager 2022-01-19 CVSS v3.1
CVSS
9.8
KEV

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Summary dbcve.org

A critical, unauthenticated remote vulnerability exists in the OpenSSO Agent component of Oracle Access Manager (versions 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0). The flaw is reachable over HTTP without credentials or user interaction and, per the CVSS vector, allows full compromise of confidentiality, integrity, and availability, enabling total takeover of the Oracle Access Manager instance. The exact vulnerability class is not specified in the advisory material provided, so the precise exploitation path (e.g., deserialization, injection, auth bypass) cannot be stated with certainty.

Mitigation

Apply the Oracle Critical Patch Update (CPU) corresponding to CVE-2021-35587 to all affected Oracle Access Manager versions, and restrict network exposure of the OpenSSO Agent HTTP endpoint to trusted networks until patched.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

96.28%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE