Impact
The flaw resides in the Centralized Thirdparty Jars component of Oracle Platform Security for Java. Even with low privileges, an attacker who can reach the platform over HTTP can trigger the vulnerability. The attack grants full control of the platform, yielding loss of confidentiality, integrity and availability. The weakness arises from improper access control (CWE‑269, CWE‑306) and an insecure deserialization flaw (CWE‑502).
Affected Systems
Affected releases are Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware. All other releases are not reported to be vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity, with an attack vector of network, low privilege and no user interaction. The EPSS score of < 1 % suggests that while the logic is easy to trigger, real‑world exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, yet the remote nature and platform takeover potential warrant immediate guarding of HTTP endpoints or network isolation. Attackers can remotely exploit the flaw via HTTP if the component is reachable, enabling complete platform compromise.
OpenCVE Enrichment