Impact
A flaw in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows an attacker with low privileges and network access via HTTP to send crafted requests that result in a full takeover of the affected installation. The vulnerability stems from inadequate access control, missing authentication, and unsafe deserialization of untrusted data. Successful exploitation grants an attacker full confidentiality, integrity, and availability control of the platform.
Affected Systems
Oracle Platform Security for Java versions 12.2.1.4.0 and 14.1.2.0.0, which are part of the Oracle Fusion Middleware suite. These versions are listed in Oracle’s CPU Jul 2026 advisory and are confirmed by the CNA as affected.
Risk and Exploitability
The CVSS base score of 8.8 classifies the issue as high severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but the low-privilege, network‑based attack vector over HTTP means that an attacker could compromise the Platform without requiring advanced access. Organizations running the affected releases should treat this as a high‑risk scenario and prioritize remediation.
OpenCVE Enrichment