Oracle Access Manager 'opensso' Deserialization RCE (CVE-2021-35587)
Description
Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent) is vulnerable to a Java Object Deserialization remote code execution vulnerability. An attacker could exploit this vulnerability using specially-crafted serialized data to execute arbitrary code on the system or to perform a denial of service attack.
Remediation
Upgrade to the latest version of Oracle Access Manager