QID 730674
Date Published: 2022-12-02
QID 730674: Oracle Access Manager Remote Code Execution (RCE) Vulnerability (cpujan2022)
Oracle Access Manager helps your enterprise facilitate the delivery of corporate functions to extended groups of employees, customers, partners, and suppliers; maintain a high level of security across applications.
The vulnerability is in the OpenSSO Agent component of the Oracle Access Manager product, which is widely used by corporations for single sign-on (SSO) as part of the Oracle Fusion Middleware suite.
Affected Versions:
Oracle Access Manager 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0
QID Detection Logic:(Unauthenticated)
QID Sends a GET request to vulnerable endpoint "oam/server/opensso/sessionservice", flags if page respond with status code 200 ok and "Oracle Corporation".
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.
- CPUJAN2022 -
www.oracle.com/security-alerts/cpujan2022.html
CVEs related to QID 730674
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cpujan2022 |
|