Description
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-22
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows an attacker with low privileges and network access via HTTP to send crafted requests that result in a full takeover of the affected installation. The vulnerability stems from inadequate access control, missing authentication, and unsafe deserialization of untrusted data. Successful exploitation grants an attacker full confidentiality, integrity, and availability control of the platform.

Affected Systems

Oracle Platform Security for Java versions 12.2.1.4.0 and 14.1.2.0.0, which are part of the Oracle Fusion Middleware suite. These versions are listed in Oracle’s CPU Jul 2026 advisory and are confirmed by the CNA as affected.

Risk and Exploitability

The CVSS base score of 8.8 classifies the issue as high severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but the low-privilege, network‑based attack vector over HTTP means that an attacker could compromise the Platform without requiring advanced access. Organizations running the affected releases should treat this as a high‑risk scenario and prioritize remediation.

Generated by OpenCVE AI on August 2, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Platform Security for Java patch released as part of the CPU Jul 2026 advisory to affected versions 12.2.1.4.0 and 14.1.2.0.0.
  • Restart the Oracle Platform Security for Java services to ensure the patch is applied.
  • If patching cannot be performed immediately, block all external HTTP traffic to the Platform Security for Java endpoints until the update is installed.

Generated by OpenCVE AI on August 2, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Centralized Third‑Party Jars Deserialization Vulnerability Allows Remote Takeover

Sat, 01 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote HTTP Vulnerability Enables Full Compromise of Oracle Platform Security for Java
Weaknesses CWE-284
CWE-285
CWE-730

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote HTTP Vulnerability Enables Full Compromise of Oracle Platform Security for Java
Weaknesses CWE-284
CWE-285
CWE-730

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-306
CWE-502
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle platform Security For Java
CPEs cpe:2.3:a:oracle:platform_security_for_java:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:platform_security_for_java:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle platform Security For Java
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Platform Security For Java
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:32:06.647Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60373

cve-icon Vulnrichment

Updated: 2026-07-23T14:32:02.617Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T23:16:36.530

Modified: 2026-07-24T15:17:27.373

Link: CVE-2026-60373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T17:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-502

    Deserialization of Untrusted Data