Executive brief
A vulnerability exists in Oracle Platform Security for Java, a component used to manage security policies and identities within Oracle Fusion Middleware environments. An attacker with basic user access to the network can exploit this flaw to take full control of the security platform. This could lead to unauthorized access to sensitive data, modification of security settings, or disruption of integrated business applications.
Technical details
This vulnerability affects the Centralized Thirdparty Jars component within Oracle Platform Security for Java (Oracle Fusion Middleware). It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw allows an attacker to achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. While the specific CWE is not detailed in the advisory, the impact is rated as a full compromise of the security framework.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory: Published in Oracle Critical Patch Update Advisory - July 2026