Impact
This vulnerability arises from inadequate validation of centralized third‑party JAR files in Oracle Platform Security for Java. The flaw, which represents multiple weaknesses—missing authorization (CWE‑269), improper access control (CWE‑284), missing authentication (CWE‑306), and deserialization of untrusted data (CWE‑502)—allows an unauthenticated attacker with network access to execute arbitrary code, resulting in full control over the service. The CVSS 3.1 base score of 9.8 reflects complete confidentiality, integrity, and availability loss.
Affected Systems
Oracle Platform Security for Java, versions 12.2.1.4.0 and 14.1.2.0.0, are affected. Any deployment using these releases should be considered at risk.
Risk and Exploitability
The flaw is easily exploitable over HTTP without authentication. Attackers need only reach the service, and the CVSS vector indicates a network attack with low effort and no user interaction. The EPSS score of <1% indicates a low but non‑zero probability of exploitation in the wild. The vulnerability is not yet listed in CISA’s KEV catalog, so no publicly known exploit is confirmed, yet the high severity warrants urgent action.
OpenCVE Enrichment