Executive brief
Oracle Platform Security for Java, a component of Oracle Fusion Middleware used for managing security policies and identities, contains a vulnerability in its centralized third-party libraries. A remote attacker with low-level user credentials can exploit this flaw over the network to gain full control of the security platform. This could lead to unauthorized access to sensitive data, modification of security settings, and disruption of services relying on the middleware.
Technical details
A vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java (part of Oracle Fusion Middleware). The flaw is easily exploitable by a remote attacker with low privileges (PR:L) via the HTTP protocol. Successful exploitation allows for a complete compromise of the product, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). Affected versions include 12.2.1.4.0 and 14.1.2.0.0. While the specific CWE is not detailed in the advisory, the impact is described as a full system takeover.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-22: disclosed: Initial publication of CVE-2026-60455
- 2026-07-22: advisory: Oracle Critical Patch Update July 2026 released