Executive brief
Oracle Platform Security for Java is a critical security component of Oracle Fusion Middleware that handles authentication and access control across enterprise systems. An unauthenticated attacker can exploit a vulnerability in the bundled third-party libraries via SOAP protocol to gain complete control over the affected system, potentially compromising all applications and data protected by this component.
Technical details
A vulnerability exists in Oracle Platform Security for Java's Centralized Thirdparty Jars component (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via SOAP, requiring no authentication, user interaction, or special conditions. Successful exploitation allows complete system takeover with high impact to confidentiality, integrity, and availability. The vulnerability likely involves a deserialization or injection flaw in the third-party library components. Patch availability is expected from Oracle's security advisory channel.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed