CVE-2021-35587: critical vulnerability in Oracle Corporation Access Manager
Published · Updated
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 9.8epss 96%
from disclosure to weapon701 days
Published on NVDJan 19
1st PoC+701d
metasploitJan 19
CISA KEV+313d
exploitation probability
96%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-12-19
Apply updates per vendor instructions.
In short
Oracle Access Manager has a critical flaw that lets attackers take over the system without needing to log in. An attacker can access it over the network and gain complete control of the authentication service.
Technical detail
Unauthenticated remote code execution vulnerability in Oracle Access Manager (OpenSSO Agent) via HTTP. Requires only network access with no authentication, pre-conditions, or user interaction. Successful exploitation results in complete system compromise affecting confidentiality, integrity, and availability.
Summary generated and translated by AI from the official description.
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).