Description
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-22
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in Oracle Platform Security for Java’s support for centralized third‑party JARs. An attacker with only low privileges who can reach the product over HTTP can exploit an easily exploitable flaw to compromise the entire platform, gaining full control and exposing the confidentiality, integrity, and availability of all data and services managed by the component.

Affected Systems

Affected variants are Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0.0. The exploit is effective on the specific Oracle Fusion Middleware component that handles third‑party JARs within both of these releases.

Risk and Exploitability

The risk is high, reflected in a CVSS 3.1 score of 9.9 with network access as the attack vector, requiring only low privileges to succeed. The EPSS indicates a very low but non‑zero exploitation probability (<1%). Although it is not listed in the CISA KEV catalog, the severity remains significant. The vulnerability can be leveraged remotely from any networked host capable of contacting the exposed HTTP endpoints, allowing an attacker to fully take over the Oracle Platform Security for Java environment, including affecting other products if they rely on the compromised component.

Generated by OpenCVE AI on August 3, 2026 at 23:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0.0 as described in Oracle’s CPU July 2026 advisory.
  • Configure firewalls or access control lists to restrict HTTP traffic to the Oracle Platform Security for Java service to only trusted IP ranges and privileged users.
  • Enforce strict access control on the JAR ingestion endpoints, ensuring that only authenticated administrative accounts can upload or manage third‑party JARs.

Generated by OpenCVE AI on August 3, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Oracle Java Platform Security Remote Takeover via Low-Privilege HTTP

Thu, 30 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Oracle Java Platform Security Remote Takeover via Low-Privilege HTTP

Tue, 28 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Low‑Privilege HTTP Access in Oracle Platform Security for Java

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Low‑Privilege HTTP Access in Oracle Platform Security for Java

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-502
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle platform Security For Java
CPEs cpe:2.3:a:oracle:platform_security_for_java:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:platform_security_for_java:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle platform Security For Java
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Platform Security For Java
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:34:44.889Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60369

cve-icon Vulnrichment

Updated: 2026-07-23T14:34:40.968Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T23:16:36.087

Modified: 2026-07-24T15:17:44.540

Link: CVE-2026-60369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:15:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-502

    Deserialization of Untrusted Data