Identity Management (MOSC)

MOSC Banner

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO A

Oracle Access Manager , Oracle Identity Managment, Oracle forms/Reports, WLS, OHS 12.2.1.4

SSO configured.


The following is security scan result from Oracle Forms and Reports, OHS home.

Any one give me instructions/hints how to remediate?


Thanks

----------------------------

The version of Oracle Access Manager installed on the remote host is affected by the following vulnerability as noted in the January 2022 CPU advisory

 - Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent).

  Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable   vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access   Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center