Impact
A flaw in Oracle Platform Security for Java allows an unauthenticated adversary with network access to LDAP to bypass authentication and fully compromise the product. The vulnerability is rated high on CVSS 3.1 with a base score of 9.8, reflecting severe impacts on confidentiality, integrity, and availability. The weakness falls under authentication bypass and insufficient access control.
Affected Systems
Versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Platform Security for Java, part of Oracle Fusion Middleware, are affected. No other products or versions are listed as vulnerable.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating very low exploitation probability, and the issue is not listed in CISA’s KEV catalog. The attack vector requires network connectivity to the LDAP service used by the product and exploits an unauthenticated access flaw; successful exploitation results in full control of the platform.
OpenCVE Enrichment