Impact
Oracle Platform Security for Java, part of Oracle Fusion Middleware, is vulnerable to a low‑privilege remote attack that enables an adversary with network access over HTTP to compromise the service and take full control. The weakness is identified as CWE‑1021 and results in a high‑severity impact on confidentiality, integrity, and availability, with a CVSS 3.1 base score of 7.5.
Affected Systems
Versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Platform Security for Java are affected. These correspond to the Oracle Fusion Middleware product suite and are typically exposed on standard HTTP ports unless further secured.
Risk and Exploitability
The vulnerability can be exploited remotely via HTTP; only low‑privilege credentials are required. The attack has no user interaction and high attack complexity, making it potentially exploitable by many attackers with moderate skill. EPSS indicates a very low but non–zero exploitation probability (<1 %). The CVSS score reflects significant confidentiality, integrity, and availability risk, and the issue is not listed in the CISA KEV catalog, meaning it remains a notable threat when the affected process is reachable.
OpenCVE Enrichment