Executive brief
Oracle Platform Security for Java, a component of Oracle Fusion Middleware used for managing security services in enterprise applications, contains a critical vulnerability. An unauthenticated attacker can exploit this flaw over the network via HTTP to gain full control over the affected component. This could lead to a complete compromise of the security framework, potentially exposing sensitive data and impacting the availability of business operations.
Technical details
A critical vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (Oracle Fusion Middleware). The flaw is easily exploitable by an unauthenticated remote attacker via the HTTP protocol. Successful exploitation allows for a complete takeover of the Oracle Platform Security for Java environment, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. While the specific vulnerability class (e.g., RCE, deserialization) is not explicitly named in the advisory, the CVSS score and 'takeover' description suggest a high-impact remote code execution or authentication bypass. Users should refer to the Oracle Critical Patch Update Advisory for July 2026 for remediation steps.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-22: disclosed: Initial disclosure by Oracle
- 2026-07-22: advisory: NVD publication date