cbcvebase.
CVE-2018-2879
published 2018-04-19

CVE-2018-2879: Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are affected…

PriorityP268critical9CVSS 3.0
AVNACHPRNUINSCCHIHAH
EPSS
22.15%
97.4th percentile
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. Note: Please refer to Doc ID My Oracle Support Note 2386496.1 for instructions on how to address this issue. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

Affected

4 ranges
VendorProductVersion rangeFixed in
oracleaccess_manager
oracleaccess_manager
oracle_corporationaccess_manager
oracle_corporationaccess_manager

Detection & IOCsextracted from sources · hover to see the quote

cookieOAMAuthnCookie
otherencquery
otherencreply
  • Monitor HTTP requests for the presence of the `encquery` parameter, which is the attack surface for the padding oracle exploit against Oracle Access Manager.
  • Detect forged or anomalous `OAMAuthnCookie` values in HTTP requests; attackers can encrypt arbitrary authentication cookies using the padding oracle to achieve authentication bypass.
  • Look for high-volume, repeated HTTP requests to Oracle Access Manager endpoints with varying `encquery`, `encreply`, or `OAMAuthnCookie` values — characteristic of padding oracle probing (CBC bit-flipping/padding oracle enumeration).
  • Flag use of the OAMBuster tool (oambuster.py) or requests matching its pattern against OAM login endpoints; the tool automates the padding oracle attack.
  • The attack is conducted over HTTP from an unauthenticated network position; alert on unauthenticated access patterns to OAM Authentication Engine endpoints with malformed or iteratively modified encrypted parameters.
  • ·The PoC required target-specific modifications (e.g., adding a consent cookie) before it would function correctly against a given OAM deployment, meaning generic tool signatures may miss adapted variants.
  • ·Affected versions are specifically 11.1.2.3.0 and 12.2.1.3.0; detections and mitigations should be scoped to these versions of Oracle Access Manager.
  • ·Oracle's official remediation guidance is contained in My Oracle Support Note 2386496.1, which should be consulted for patch instructions.

CVSS provenance

nvdv3.09.0CRITICALCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.