Impact
This vulnerability exists in Oracle Platform Security for Java’s support for centralized third‑party JARs. An attacker with only low privileges who can reach the product over HTTP can exploit an easily exploitable flaw to compromise the entire platform, gaining full control and exposing the confidentiality, integrity, and availability of all data and services managed by the component.
Affected Systems
Affected variants are Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0.0. The exploit is effective on the specific Oracle Fusion Middleware component that handles third‑party JARs within both of these releases.
Risk and Exploitability
The risk is high, reflected in a CVSS 3.1 score of 9.9 with network access as the attack vector, requiring only low privileges to succeed. The EPSS indicates a very low but non‑zero exploitation probability (<1%). Although it is not listed in the CISA KEV catalog, the severity remains significant. The vulnerability can be leveraged remotely from any networked host capable of contacting the exposed HTTP endpoints, allowing an attacker to fully take over the Oracle Platform Security for Java environment, including affecting other products if they rely on the compromised component.
OpenCVE Enrichment