CVE-2021-35587
Summary
| CVE | CVE-2021-35587 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-19 12:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
Risk And Classification
EPSS: 0.962840000 probability, percentile 0.998740000 (date 2026-07-22)
CISA KEV: Listed on 2022-11-28; due 2022-12-19; ransomware use Unknown
Problem Types: NVD-CWE-Other
CISA Known Exploited Vulnerability
| Vendor | Oracle |
|---|---|
| Product | Fusion Middleware |
| Name | Oracle Fusion Middleware Unspecified Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.oracle.com/security-alerts/cpujan2022.html; https://nvd.nist.gov/vuln/detail/CVE-2021-35587 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Access Manager | 11.1.2.3.0 | All | All | All |
| Application | Oracle | Access Manager | 12.2.1.3.0 | All | All | All |
| Application | Oracle | Access Manager | 12.2.1.4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - January 2022 | MISC | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.