Impact
A flaw in Oracle Platform Security for Java allows an attacker with low privileges to exploit the SOAP service. It is inferred that this can grant the attacker full control over the application, leading to loss of confidentiality, integrity, and availability. The vulnerability resides in the Centralized Thirdparty Jars component and allows the attacker to compromise and take over Oracle Platform Security for Java.
Affected Systems
Oracle Platform Security for Java in Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0, are affected by this vulnerability.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.8 indicates high severity. The EPSS score is < 1%, showing a very low probability that the vulnerability will be exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need network access to the SOAP endpoint and only low privilege. The low EPSS score indicates a low probability of exploitation.
OpenCVE Enrichment