PT-2022-1818 · Oracle · Oracle Access Manager

Jangggg

+1

·

Published

2022-01-19

·

Updated

2026-06-16

·

CVE-2021-35587

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Access Manager versions 11.1.2.3.0 through 12.2.1.4.0
Description The issue is related to errors in processing HTTP requests in the Oracle Access Manager component of Oracle Fusion Middleware. This can allow a remote attacker to execute arbitrary code. Successful attacks can result in the takeover of Oracle Access Manager. The vulnerability can be easily exploited by an unauthenticated attacker with network access via HTTP.
Recommendations For versions 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01248
CVE-2021-35587

Affected Products

Oracle Access Manager