Impact
The vulnerability is located in the Centralized Thirdparty Jars component of Oracle Platform Security for Java. An unauthenticated attacker with network access via HTTP can compromise the service, potentially leading to a full takeover that compromises confidentiality, integrity, and availability for the platform and may affect other Oracle Fusion Middleware products because of the scope change.
Affected Systems
The vulnerability affects Oracle’s Platform Security for Java versions 12.2.1.4.0 and 14.1.2.0.0; no other products or versions are currently listed by Oracle as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 10.0 signals that the impact is catastrophic if exploited. Although the EPSS score is below 1%, the severity of the flaw indicates a high potential for compromise. The vulnerability is not listed in the CISA KEV catalog, yet the combination of being unauthenticated, having a network-based attack vector, and the potential for complete system compromise suggests a significant threat. Attackers can reach the vulnerable component directly over HTTP, assuming the service is network reachable from the attacker’s location.
OpenCVE Enrichment