SOURCE FACT
Oracle · Fusion Middleware
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
Required action
Apply updates per vendor instructions.
CISA notes
https://www.oracle.com/security-alerts/cpujan2022.html; https://nvd.nist.gov/vuln/detail/CVE-2021-35587
View source evidence →