Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspujun2026.html |
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Exploit Grants Data Manipulation and Partial Denial in Oracle Access Manager | |
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Tue, 16 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). | |
| First Time appeared |
Oracle
Oracle access Manager |
|
| CPEs | cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle access Manager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-06-17T15:37:32.198Z
Reserved: 2026-04-01T20:03:40.837Z
Link: CVE-2026-35314
Updated: 2026-06-17T15:25:39.954Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-17T20:30:04Z