Impact
This vulnerability resides in the Centralized Third‑Party Jars component of Oracle Platform Security for Java and allows a low‑privileged attacker who can reach the service over HTTP to compromise the platform. A successful exploit can lead to full takeover of the Platform Security for Java, enabling arbitrary code execution with the privileges of the service account, and causing total loss of confidentiality, integrity, and availability. The flaw carries a CVSS v3.1 Base Score of 8.8, highlighting high impacts across all security attributes.
Affected Systems
Oracle Platform Security for Java versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. The vulnerability is specific to the Centralized Third‑Party Jars component exposed through the platform’s HTTP interface and includes all deployments that rely on that component.
Risk and Exploitability
The EPSS score is below 1 %, indicating a low probability of public exploitation, but the CVSS score denotes a severe impact. The flaw can be exercised remotely via HTTP without the need for user interaction, requiring only low privileges or local network access. Attackers who can reach the Platform Security for Java endpoint can rapidly exploit the vulnerability. Since the flaw is not yet listed in the CISA KEV catalog, it has not been confirmed as a known exploitation campaign, but the combination of ease of exploitation and high impact warrants high‑priority remediation.
OpenCVE Enrichment