CVE-2021-35587
published 2022-01-19CVE-2021-35587: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-12-19
Exploited in the wild
EPSS
96.28%
99.9th percentile
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | access_manager | — | — |
| oracle | access_manager | — | — |
| oracle | access_manager | — | — |
| oracle_corporation | access_manager | — | — |
| oracle_corporation | access_manager | — | — |
| oracle_corporation | access_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring HTTP GET requests to /oam/server/opensso/sessionservice from unauthenticated sources. ↗
- →Responses from a vulnerable Oracle Access Manager instance will contain the HTTP response headers 'x-oracle-dms-ecid' and/or 'x-oracle-dms-rid' alongside HTTP 200 status. ↗
- →Vulnerable OAM instances can be fingerprinted via Shodan using the page title 'Oracle Access Management' or the presence of '/oam/pages/css/login_page.css' in HTML. ↗
- →Check Point IPS signature name for this CVE can be used for network-level detection. ↗
- →The vulnerability is an unauthenticated deserialization of untrusted data in the OpenSSO Agent component; monitor for suspicious Java deserialization payloads sent via HTTP to OAM endpoints. ↗
- ·Only Oracle Access Manager versions 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0 are affected; other versions are not in scope for this CVE. ↗
- ·The vulnerability is exploitable over HTTP with no authentication required and no user interaction, making it trivially exploitable from the network. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Oracle Fusion Middleware Unspecified Vulnerability
cisa·2022-11-28·CVSS 9.8
CVE-2021-35587 [CRITICAL] CWE-502 Oracle Fusion Middleware Unspecified Vulnerability
Vulnerability: Oracle Fusion Middleware Unspecified Vulnerability
Affected: Oracle Fusion Middleware
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
Required Action: Apply updates per vendor instructions.
Notes: https://www.oracle.com/security-alerts/cpujan2022.html; https://nvd.nist.gov/vuln/detail/CVE-2021-35587
Remediation Due Date: 2022-12-19
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: OpenSSO Agent — CVE-2021-35587
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2021-35587 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: OpenSSO Agent — CVE-2021-35587
Oracle Oracle Fusion Middleware Risk Matrix: OpenSSO Agent vulnerability
CVE: CVE-2021-35587
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
GHSA
GHSA-x3jv-936g-xqj4: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent)
ghsa_unreviewed·2022-01-20
CVE-2021-35587 [CRITICAL] CWE-306 GHSA-x3jv-936g-xqj4: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent)
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle Fusion Middleware Unspecified Vulnerability
vulncheck·2021·CVSS 9.8
CVE-2021-35587 [CRITICAL] CWE-502 Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
Affected: Oracle Fusion Middleware
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-01&host_type=src&vulnerability=cve-2021-35587; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-03&host_type=src&vulnerability=cve-2021-35587; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-05&host_type=src&vulnerability=cve-2021-35587; h
Suricata
ET EXPLOIT Possible Oracle Access Manager RCE Attempt (CVE-2021-35587)
suricata·2022-03-10·CVSS 9.8
CVE-2021-35587 [CRITICAL] ET EXPLOIT Possible Oracle Access Manager RCE Attempt (CVE-2021-35587)
ET EXPLOIT Possible Oracle Access Manager RCE Attempt (CVE-2021-35587)
Rule: alert http1 any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Oracle Access Manager RCE Attempt (CVE-2021-35587)"; flow:established,to_server; http.request_line; content:"POST /oam/server/opensso/sessionservice HTTP/1.1"; fast_pattern; http.request_body; content:"svcid"; content:"|5b|CDATA"; content:"requester|3d|"; distance:0; nocase; reference:cve,2021-35587; classtype:attempted-admin; sid:2035429; rev:3; metadata:attack_target Server, created_at 2022_03_10, cve CVE_2021_35587, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_04_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190
Metasploit
Oracle Access Manager unauthenticated Remote Code Execution
metasploit
Oracle Access Manager unauthenticated Remote Code Execution
Oracle Access Manager unauthenticated Remote Code Execution
This module exploits an unauthenticated deserialization of untrusted data vulnerability in the OpenSSO Agent component of the Oracle Access Manager (OAM) product. The affected product versions are 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0.
Nuclei
Oracle Access Manager - Remote Code Execution
nuclei·CVSS 9.8
CVE-2021-35587 [CRITICAL] Oracle Access Manager - Remote Code Execution
Oracle Access Manager - Remote Code Execution
The Oracle Access Manager portion of Oracle Fusion Middleware (component: OpenSSO Agent) is vulnerable to remote code execution. Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. This is an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle Access Manager.
Template:
id: CVE-2021-35587
info:
name: Oracle Access Manager - Remote Code Execution
author: cckuailong
severity: critical
description: |
The Oracle Access Manager portion of Oracle Fusion Middleware (component: OpenSSO Agent) is vulnerable to remote code execution. Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. This is an easily exploitable vulnerability
Tenable
CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability
blogs_tenable·2026-03-20·CVSS 9.8
[CRITICAL] CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Qualys Threat Research Unit: Threat Thursdays, December 2022
blogs_qualys·2022-12-29
Qualys Threat Research Unit: Threat Thursdays, December 2022
## Table of Contents
From the Qualys Blogs
New Tools & Techniques
New Vulnerabilities
Threat Thursdays Webinar
Welcome to the fourth edition of the Qualys Threat Research Unit’s (TRU) “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. This also happens to be the last edition for the year. Feedback on our third edition, Qualys Threat Research Thursday , is more than welcome. We would love to hear from you!
## From the Qualys Blogs
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
Dissecting the Empire C2 Framework – In this blog post, we take a quick dive into Empire, a popular open-source post-exploitation fra
Qualys
Qualys Threat Research Unit: Threat Thursdays, December 2022 | Qualys
blogs_qualys·2022-12-29
Qualys Threat Research Unit: Threat Thursdays, December 2022 | Qualys
#### Table of Contents
- From the Qualys Blogs
- New Tools & Techniques
- New Vulnerabilities
- Threat Thursdays Webinar
Welcome to the fourth edition of the Qualys Threat Research Unit’s (TRU) “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. This also happens to be the last edition for the year. Feedback on our third edition, Qualys Threat Research Thursday, is more than welcome. We would love to hear from you!
## From the Qualys Blogs
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
- Dissecting the Empire C2 Framework – In this blog post, we take a quick dive into Empire, a popular open-source post-exploita
Checkpoint
5th December – Threat Intelligence Report
blogs_checkpoint·2022-12-05
CVE-2022-4262 5th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Cyber criminals who breached Australian Medibank’s systems have released another batch of data onto the dark web, claiming that the files contain all data harvested in the former heist that impacted 9.7 million customers in October 2022. Medibank has confirmed the data breach.
Colombian healthcare provider Keralty, opera
arXiv
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
arxiv_fulltext·2026-03
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
Downsides of Smartness Across Edge-Cloud Continuum in Modern Industry
Akhil Gupta Chigullapally^1, Sharvan Vittala^1, Razin Farhan Hussian^2, Mohsen Amini Salehi^3
^1Department of Computer Science and Engineering, University of North Texas (UNT)
\akhilguptachigullapally, [email protected]\@my.unt.edu
^2Versaterm Public Safety Inc., Canada
[email protected]
^3High Performance Cloud Computing (HPCC) Lab, Department of Computer Science and Engineering, University of North Texas (UNT)
[email protected]
## Abstract
The fast pace of modern AI is rapidly transforming traditional industrial systems into vast,
intelligent—and potentially unmanned—autonomous operational environments driven by AI-based solutions. These solutions leverage various forms of machine lea
2022-01-19
Published
2022-11-28
Added to CISA KEV
Exploited in the wild