Impact
The vulnerability resides in the Oracle Platform Security for Java component of Oracle Fusion Middleware and represents an information disclosure (CWE-200), an authorization bypass (CWE-269), and an improper access control (CWE-284). It permits an attacker who owns a low-privilege account and who can reach the physical communication segment that the Java component uses to obtain control over the entire Platform Security for Java. Successful exploitation can lead to full takeover, compromising confidentiality, integrity, and availability of the entire component and potentially affecting other dependent Oracle Fusion Middleware products.
Affected Systems
Affected are Oracle Corporation’s Oracle Platform Security for Java version 12.2.1.4.0 and 14.1.2.0.0, which are part of the Oracle Fusion Middleware suite.
Risk and Exploitability
The CVSS 3.1 score of 8.0 indicates a high severity, with the vector stating AV:A, AC:H, PR:L, UI:N, S:C. The attack requires physical access to the hardware segment, but once the attacker gains a foothold the impact is catastrophic. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV. The most likely attack path is a local attacker connecting to the system’s communication segment and leveraging the flaw to execute arbitrary code as the Platform Security for Java process.
OpenCVE Enrichment