cbcvebase.
CVE-2021-35587
published 2022-01-19

CVE-2021-35587: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-12-19
Exploited in the wild
EPSS
96.28%
99.9th percentile
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

6 ranges
VendorProductVersion rangeFixed in
oracleaccess_manager
oracleaccess_manager
oracleaccess_manager
oracle_corporationaccess_manager
oracle_corporationaccess_manager
oracle_corporationaccess_manager

Detection & IOCsextracted from sources · hover to see the quote

url/oam/server/opensso/sessionservice
path/oam/pages/css/login_page.css
path/oam/pages/css/general.css
  • Detect exploitation attempts by monitoring HTTP GET requests to /oam/server/opensso/sessionservice from unauthenticated sources.
  • Responses from a vulnerable Oracle Access Manager instance will contain the HTTP response headers 'x-oracle-dms-ecid' and/or 'x-oracle-dms-rid' alongside HTTP 200 status.
  • Vulnerable OAM instances can be fingerprinted via Shodan using the page title 'Oracle Access Management' or the presence of '/oam/pages/css/login_page.css' in HTML.
  • Check Point IPS signature name for this CVE can be used for network-level detection.
  • The vulnerability is an unauthenticated deserialization of untrusted data in the OpenSSO Agent component; monitor for suspicious Java deserialization payloads sent via HTTP to OAM endpoints.
  • ·Only Oracle Access Manager versions 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0 are affected; other versions are not in scope for this CVE.
  • ·The vulnerability is exploitable over HTTP with no authentication required and no user interaction, making it trivially exploitable from the network.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.