Executive brief
Oracle Platform Security for Java, a component of Oracle Fusion Middleware used for managing security policies and identities, contains a vulnerability in its third-party library components. An attacker with low-level access to the network could exploit this flaw to gain full control over the security platform. A successful attack could lead to a complete takeover of the affected system, potentially compromising sensitive data and service availability.
Technical details
This vulnerability exists within the Centralized Thirdparty Jars component of Oracle Platform Security for Java (Oracle Fusion Middleware). It is classified as difficult to exploit (High Attack Complexity) but allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation results in a complete loss of confidentiality, integrity, and availability (takeover of the product). The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-22: advisory: Initial advisory published by Oracle and NVD.