Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-39412


Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).


Published

2022-10-18T21:15:15.450

Last Modified

2024-11-21T07:18:14.570

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle access_manager 12.2.1.4.0 Yes

References