Executive brief
Oracle Platform Security for Java is a core security component of Oracle Fusion Middleware that manages authentication and authorization. An unauthenticated attacker on the network can exploit a vulnerability via LDAP to achieve complete compromise of the Platform Security for Java system, resulting in potential takeover of authentication and access controls across dependent Oracle applications.
Technical details
The vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java and is exploitable via LDAP protocol with no authentication required. Affected versions are 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated network attacker can exploit this to achieve remote code execution or full system compromise. The attack has low complexity and requires no user interaction. Patch status should be confirmed through Oracle's official security advisory.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed