peter bassill · operator
$ cve CVE-2021-35587 JSON

CVE-2021-35587 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 96.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-12-19.

Description

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS96.28% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-306
On CISA KEVyes — remediate by 2022-12-19
Public exploitnone known
Published2022-01-19
Last modified2026-06-17

CISA KEV

NameOracle Fusion Middleware Unspecified Vulnerability
Added2022-11-28
Due2022-12-19
Vendor / productOracle / Fusion Middleware
Ransomware usenone reported

Affected (1)

VendorProduct
oracleaccess manager

References

→ the Explorer  ·  watch your stack  ·  NVD