CVE-2021-35587criticalunder attackCWE-306

CVE-2021-35587: critical vulnerability in Oracle Corporation Access Manager

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 96%
from disclosure to weapon701 days
Published on NVDJan 19
1st PoC+701d
metasploitJan 19
CISA KEV+313d
exploitation probability
96%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-12-19

Apply updates per vendor instructions.

In short

Oracle Access Manager has a critical flaw that lets attackers take over the system without needing to log in. An attacker can access it over the network and gain complete control of the authentication service.

Technical detail

Unauthenticated remote code execution vulnerability in Oracle Access Manager (OpenSSO Agent) via HTTP. Requires only network access with no authentication, pre-conditions, or user interaction. Successful exploitation results in complete system compromise affecting confidentiality, integrity, and availability.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.