ZeroHour

CVE-2021-35587

KEVniche

Unauthenticated RCE in Oracle Access Manager (OpenSSO Agent)

CISA: Oracle Fusion Middleware Unspecified Vulnerability

CVSS 3.1
9.8 critical
EPSS
96%p100
Published
()
KEV added
AI analysis

CVE-2021-35587 is a critical (CVSS 9.8) missing-authentication flaw (CWE-306) in the OpenSSO Agent component of Oracle Access Manager, part of Oracle Fusion Middleware. An unauthenticated attacker with network access can send crafted HTTP requests to the affected component and, because the endpoint requires no authentication, achieve takeover of Oracle Access Manager — effectively pre-authentication remote code execution with high impact on confidentiality, integrity, and availability. Organizations running Oracle Access Manager 11.1.2.3.0, 12.2.1.3.0, or 12.2.1.4.0 are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-11-28, and security press reported more than 150 internet-exposed Oracle Access Management systems. EPSS assigns a 96.3% probability of exploitation within 30 days, although no public proof-of-concept code is known.

What to do: Apply Oracle's update for CVE-2021-35587 per vendor instructions (delivered via the Oracle Critical Patch Update covering this flaw) to bring Access Manager 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0 to a fixed release; this is the required action in CISA's KEV entry. Until patched, restrict HTTP access to OpenSSO Agent/Access Manager endpoints at the perimeter and review access logs for signs of unauthenticated exploitation.

Affected
Oracle Access Manager (component: OpenSSO Agent) of Oracle Fusion Middleware11.1.2.3.0, 12.2.1.3.0, 12.2.1.4.0
Estimated exposure
niche≈150+ internet-exposed Oracle Access Manager systems identified by public scans — Internet-wide scans reported in trade press identified more than 150 Oracle Access Management systems reachable by this bug; the broader enterprise installed base is larger but unknown, so the exposed-system count is the best available…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle Fusion Middleware
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
access manager
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news