Impact
The vulnerability resides in the Centralized Thirdparty Jars component of Oracle Platform Security for Java. It is an improper authorization flaw (CWE‑284) that can be exploited by any low‑privileged user who has logged onto the infrastructure where the product is running. An attacker who succeeds can compromise the entire Platform Security for Java installation, resulting in full loss of confidentiality, integrity.
Affected Systems
Oracle Corporation’s Oracle Platform Security for Java is affected for versions 12.2.1.4.0 and 14.1.2.0.0 only.
Risk and Exploitability
The CVSS v3.1 score of 7.8 indicates a high impact with local access, low complexity, and low privileges required. The EPSS score of less than 1 % shows that exploitation is currently very unlikely but still possible. The lack of KEV listing means no confirmed widespread exploitation is known. The likely attack vector is a local attacker who can log into the host that runs the Platform Security for Java process and then exercises the compromised authorization control to take over the application.
OpenCVE Enrichment