id: oracle-access-management info: name: Oracle Access Management Login Panel - Detect author: righettod severity: info description: Oracle Access Management login panel was detected. reference: - https://www.oracle.com/security/identity-management/access-management/ classification: cpe: cpe:2.3:a:oracle:access_manager:*:*:*:*:*:*:*:* metadata: verified: true max-request: 2 vendor: oracle product: access_manager shodan-query: - "http.title:\"Oracle Access Management\"" - http.title:"oracle access management" - http.html:"/oam/pages/css/login_page.css" fofa-query: - "title=\"Oracle Access Management\"" - title="oracle access management" - body="/oam/pages/css/login_page.css" google-query: intitle:"oracle access management" tags: panel,oracle,login,detect http: - method: GET path: - "{{BaseURL}}/oam/pages/login.jsp" - "{{BaseURL}}" stop-at-first-match: true host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word part: body words: - "Login - Oracle Access Management" - "/oam/pages/images" - "/oam/server/" condition: or extractors: - type: regex part: body group: 1 regex: - '(?i)Login\s+-\s+Oracle\s+Access\s+Management\s+([a-z0-9]+)' # digest: 4b0a00483046022100cb945c8cedf8d9f9840fed89fee44f9f4ef3657830b476b91ee2c6b4b9ce0782022100d5ea432b3dd0b50f61ef94a834cd86da00f6f08b893e45b3547893a3cc1bdb3c:922c64590222798bb761d5b6d8e72950