Description
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-22
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle Platform Security for Java component of Oracle Fusion Middleware and represents an information disclosure (CWE-200), an authorization bypass (CWE-269), and an improper access control (CWE-284). It permits an attacker who owns a low-privilege account and who can reach the physical communication segment that the Java component uses to obtain control over the entire Platform Security for Java. Successful exploitation can lead to full takeover, compromising confidentiality, integrity, and availability of the entire component and potentially affecting other dependent Oracle Fusion Middleware products.

Affected Systems

Affected are Oracle Corporation’s Oracle Platform Security for Java version 12.2.1.4.0 and 14.1.2.0.0, which are part of the Oracle Fusion Middleware suite.

Risk and Exploitability

The CVSS 3.1 score of 8.0 indicates a high severity, with the vector stating AV:A, AC:H, PR:L, UI:N, S:C. The attack requires physical access to the hardware segment, but once the attacker gains a foothold the impact is catastrophic. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV. The most likely attack path is a local attacker connecting to the system’s communication segment and leveraging the flaw to execute arbitrary code as the Platform Security for Java process.

Generated by OpenCVE AI on August 3, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch issued in the July 2026 CPU for Platform Security for Java.
  • Enforce network segmentation so that the physical communication segment used by Platform Security for Java is isolated and only accessible to trusted hosts.
  • Verify that only trusted users have administrative rights on the Java runtime environment and that the Platform Security for Java process runs with the minimal privileges required.

Generated by OpenCVE AI on August 3, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation to Platform Security for Java via Physical Communication Access

Sat, 01 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation to Platform Security for Java via Physical Communication Access

Tue, 28 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Platform Security for Java Vulnerability Allowing Takeover via Physical Communication Segment

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Platform Security for Java Vulnerability Allowing Takeover via Physical Communication Segment

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle platform Security For Java
CPEs cpe:2.3:a:oracle:platform_security_for_java:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:platform_security_for_java:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle platform Security For Java
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Platform Security For Java
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:29:43.268Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60371

cve-icon Vulnrichment

Updated: 2026-07-23T14:29:39.002Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T23:16:36.317

Modified: 2026-07-24T15:17:35.667

Link: CVE-2026-60371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control