Impact
The flaw is in the Centralized Third‑party Jars component of Oracle Platform Security for Java and allows an attacker to connect over HTTP without any authentication. If exploited, the attacker can take full control of the application, resulting in a total loss of confidentiality, integrity and availability for the affected system. The weakness is reflected in several CWEs, including improper authentication and deserialization issues.
Affected Systems
Oracle Platform Security for Java, a component of Oracle Fusion Middleware, is impacted for versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is specifically tied to HTTP interfaces exposed by the Centralized Third‑party Jars service.
Risk and Exploitability
With a CVSS v3.1 base score of 9.8, this is a critical flaw that can be remotely triggered over a network with no prior credentials. The EPSS score is less than 1 percent, indicating that the exploitation probability is low but non‑negligible, and the vulnerability is not yet listed in CISA KEV. Nonetheless, the ease of exploitation—no authentication or UI required—makes the risk high for any exposed system.
OpenCVE Enrichment