Executive brief
Oracle Platform Security for Java, a component of Oracle Fusion Middleware used for managing security across Java applications, contains a high-severity vulnerability. An attacker with low-level access to the same local network segment as the affected hardware could potentially take full control of the security platform. This could lead to a total compromise of the system's confidentiality and integrity, potentially impacting other connected business applications.
Technical details
This vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as difficult to exploit (AC:H) and requires the attacker to have low-privileged access (PR:L) to the physical communication segment (AV:A) attached to the target hardware. Successful exploitation results in a scope change (S:C), meaning the attacker can potentially impact other products beyond the security platform itself, leading to a complete takeover of the affected component. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-22: disclosed: Initial publication of CVE-2026-60371
- 2026-07-22: advisory: Included in Oracle Critical Patch Update (CPU) July 2026