Description
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Platform Security for Java, part of Oracle Fusion Middleware, is vulnerable to a low‑privilege remote attack that enables an adversary with network access over HTTP to compromise the service and take full control. The weakness is identified as CWE‑1021 and results in a high‑severity impact on confidentiality, integrity, and availability, with a CVSS 3.1 base score of 7.5.

Affected Systems

Versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Platform Security for Java are affected. These correspond to the Oracle Fusion Middleware product suite and are typically exposed on standard HTTP ports unless further secured.

Risk and Exploitability

The vulnerability can be exploited remotely via HTTP; only low‑privilege credentials are required. The attack has no user interaction and high attack complexity, making it potentially exploitable by many attackers with moderate skill. EPSS indicates a very low but non–zero exploitation probability (<1 %). The CVSS score reflects significant confidentiality, integrity, and availability risk, and the issue is not listed in the CISA KEV catalog, meaning it remains a notable threat when the affected process is reachable.

Generated by OpenCVE AI on August 3, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Platform Security for Java patch or upgrade recommended in Oracle’s CPU July 2026 advisory
  • Restrict network access to the Service so that only trusted IP ranges or internal networks can reach its HTTP endpoints
  • Enable comprehensive logging for the service and monitor logs for abnormal connections or configuration changes
  • If a patch is temporarily unavailable, consider isolating the Service behind a firewall or disabling exposed HTTP endpoints

Generated by OpenCVE AI on August 3, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Remote Exploit in Oracle Platform Security for Java

Sun, 02 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Remote Exploit in Oracle Platform Security for Java
Weaknesses CWE-284

Mon, 27 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Remote Exploitable Vulnerability in Oracle Platform Security for Java

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Exploitable Vulnerability in Oracle Platform Security for Java
Weaknesses CWE-284

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1021
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle platform Security For Java
CPEs cpe:2.3:a:oracle:platform_security_for_java:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:platform_security_for_java:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle platform Security For Java
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Platform Security For Java
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:33:59.271Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60370

cve-icon Vulnrichment

Updated: 2026-07-23T14:33:56.292Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T23:16:36.203

Modified: 2026-07-24T15:17:40.567

Link: CVE-2026-60370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:15:04Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames