Access Manager

Vendor:

First CVE: Oct 19, 2017 · Active for 8 years

21
Total CVEs
More Total CVEs than 94% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
9.5%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Access Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 19, 2017
8 years ago
Most Recent CVE
Jul 21, 2026
4 days ago

CVE Severity & Scoring

Access Manager21 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local1 (4.8%)
Network20 (95.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (81.0%)
High4 (19.0%)
Unknown0 (0.0%)
User Interaction
None15 (71.4%)
Unknown0 (0.0%)
Required6 (28.6%)
Privileges Required
Low4 (19.0%)
High2 (9.5%)
None15 (71.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.
Jan 19, 20229.898YESYES
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0,
Jan 15, 20209.898YESYES
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2
Apr 19, 20189.040NONO
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.
Jun 16, 20269.934NONO
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The supported version that is affected is 14.1.2.1.0. Easily ex
Jul 21, 20268.833NONO
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). Supported versions that are affected are 10.1.4.3.0, 11.1.2.3.0
Apr 19, 20189.326NONO
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0.
Jun 16, 20267.325NONO
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.
Jun 16, 20266.524NONO
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affected is 12.2.1.4.0. Easily exploitable
Oct 18, 20227.524NONO
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value,
Apr 13, 20214.824NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
2 CVEs
9.5% of CVEs· 97th percentile
Metasploit
2 CVEs
9.5% of CVEs· 97th percentile
Nuclei
1 CVE
4.8% of CVEs· 97th percentile
ExploitDB
1 CVE
4.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Access Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.1.2.1.057.70.3%00
12.2.1.4.096.912.4%11
12.2.1.3.0106.513.9%11
11.1.2.3.0136.618.5%22
10.1.4.3.027.92.2%00