Get Mystery Box with random crypto!

Oracle Access Manager Pre-Auth RCE (CVE-2021–35587 Analysis) | PT SWARM

Oracle Access Manager Pre-Auth RCE (CVE-2021–35587 Analysis)

by Jang and Peter

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability may give the attacker access to OAM server, to create any user with any privileges, or just get code execution in the victim’s server

https://testbnull.medium.com/oracle-access-manager-pre-auth-rce-cve-2021-35587-analysis-1302a4542316