Description
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-22
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Centralized Third‑Party Jars component of Oracle Platform Security for Java and allows a low‑privileged attacker who can reach the service over HTTP to compromise the platform. A successful exploit can lead to full takeover of the Platform Security for Java, enabling arbitrary code execution with the privileges of the service account, and causing total loss of confidentiality, integrity, and availability. The flaw carries a CVSS v3.1 Base Score of 8.8, highlighting high impacts across all security attributes.

Affected Systems

Oracle Platform Security for Java versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. The vulnerability is specific to the Centralized Third‑Party Jars component exposed through the platform’s HTTP interface and includes all deployments that rely on that component.

Risk and Exploitability

The EPSS score is below 1 %, indicating a low probability of public exploitation, but the CVSS score denotes a severe impact. The flaw can be exercised remotely via HTTP without the need for user interaction, requiring only low privileges or local network access. Attackers who can reach the Platform Security for Java endpoint can rapidly exploit the vulnerability. Since the flaw is not yet listed in the CISA KEV catalog, it has not been confirmed as a known exploitation campaign, but the combination of ease of exploitation and high impact warrants high‑priority remediation.

Generated by OpenCVE AI on August 4, 2026 at 15:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or release for Platform Security for Java that addresses this vulnerability.
  • Restrict access to the Platform Security for Java HTTP endpoint to trusted administrators, VPN traffic, or a dedicated network segment, blocking all other traffic.
  • Verify that the Centralized Third‑Party Jars repository contains only signed and verified jar files; quarantine or remove any unapproved third‑party libraries.
  • Enable detailed logging of jar deployment and monitor for anomalous network activity associated with Platform Security for Java.

Generated by OpenCVE AI on August 4, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle Platform Security for Java

Sun, 02 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Exploitable HTTP‑Based Takeover of Oracle Platform Security for Java via Centralized Third‑Party Jars

Thu, 30 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Exploitable HTTP‑Based Takeover of Oracle Platform Security for Java via Centralized Third‑Party Jars

Sun, 26 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Enables Platform Security for Java Compromise
Weaknesses CWE-285
CWE-502
CWE-730

Sat, 25 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1395
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Enables Platform Security for Java Compromise
Weaknesses CWE-285
CWE-502
CWE-730

Wed, 22 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle platform Security For Java
CPEs cpe:2.3:a:oracle:platform_security_for_java:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:platform_security_for_java:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle platform Security For Java
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Platform Security For Java
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:07:51.270Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60455

cve-icon Vulnrichment

Updated: 2026-07-23T15:07:44.402Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T23:16:36.753

Modified: 2026-07-24T15:17:17.297

Link: CVE-2026-60455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-1395

    Dependency on Vulnerable Third-Party Component

  • CWE-269

    Improper Privilege Management