Impact
Oracle Platform Security for Java contains an easily exploitable flaw that permits a low‑privileged attacker with network access via HTTP to gain full control of the system. The vulnerability enables compromise of confidentiality, integrity, and availability, as indicated by the CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Systems
Oracle Corporation – Oracle Platform Security for Java. Versions 12.2.1.4.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
The flaw can be leveraged remotely over HTTP; a low‑privileged attacker can send a crafted request to the target and take over the application. The CVSS score reflects a high severity, and the EPSS score of <1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but its high scoring and remote attack path make it a significant risk.
OpenCVE Enrichment