S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-35587 Scanner

CVE-2021-35587 scanner - Remote Code Execution (RCE) vulnerability in Oracle Corporation Access Manager

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
12
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-35587
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Access Managerby Oracle Corporation
11.1.2.3.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle Corporation's Access Manager is a product that helps organizations manage user access to web and enterprise applications. It provides a centralized platform for authentication, authorization, and policy-based control of resources. With Access Manager, organizations can ensure that only authorized users have access to critical resources. It is a crucial component of Oracle Fusion Middleware, supporting versions 11.1.2.3.0, 12.2.1.3.0, and 12.2.1.4.0.

Recently, the CVE-2021-35587 vulnerability was detected in the OpenSSO Agent component of Oracle Access Manager. This vulnerability allows an unauthenticated attacker with network access through HTTP to compromise the Access Manager. The vulnerability is easily exploitable and can result in a complete takeover of the Access Manager. The CVSS 3.1 Base Score for this vulnerability is 9.8, indicating a severe impact on confidentiality, integrity, and availability.

If exploited, the CVE-2021-35587 vulnerability allows an attacker to take over the Access Manager, granting them access to sensitive data and resources. Such an attack could lead to data breaches, theft of intellectual property, and financial losses due to downtime or theft. Moreover, it could damage the reputation of the organization.

At s4e.io, we provide comprehensive vulnerability assessment services that help organizations identify and mitigate vulnerabilities in their digital assets. With our pro features, you can easily and quickly learn about vulnerabilities in your systems and take action to protect them from cyber threats. Don't leave your organization's security to chance - sign up for s4e.io today!

 

REFERENCES

Solution Advice

To protect against this vulnerability, Oracle recommends applying a patch as soon as possible. Additionally, organizations can take the following precautions:

  • Restrict access to the Access Manager and related systems to authorized personnel only.
  • Monitor network traffic for unusual activity.
  • Implement network segmentation to limit the scope of the attack.
  • Use multi-factor authentication to strengthen user authentication.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.