CVE-2021-35587
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Affected products
- Oracle Access Manager
- Oracle Access Manager
- = 11.1.2.3.0, 12.2.1.3.0, 12.2.1.4.0
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 96.3% (100th percentile)
- Weakness
- CWE-306
- NVD status
- Analyzed
- Published
- 2022-01-19
CVE-2021-35587 at NVD
5 known exploits for CVE-2021-35587
Proof-of-concept code and exploit modules indexed by Sploitus
π Oracle Access Manager 12.2.1.4.0 Insecure Deserialization
Oracle Access Manager unauthenticated Remote Code Execution
π Oracle Access Manager Unauthenticated Remote Code Execution
Exploit for Missing Authentication for Critical Function in Oracle Access_Manager
Exploit for Missing Authentication for Critical Function in Oracle Access_Manager