First published: Wed Jan 19 2022(Updated: )
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
Credit: secalert_us@oracle.com secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Access Manager | =11.1.2.3.0 | |
Oracle Access Manager | =12.2.1.3.0 | |
Oracle Access Manager | =12.2.1.4.0 | |
Oracle Fusion Middleware | ||
=11.1.2.3.0 | ||
=12.2.1.3.0 | ||
=12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-35587.
The severity of CVE-2021-35587 is critical with a score of 9.8.
Oracle Fusion Middleware, specifically the Oracle Access Manager component, is affected by CVE-2021-35587.
The affected versions of Oracle Access Manager are 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0.
An unauthenticated attacker with network access via HTTP can easily exploit CVE-2021-35587.