Executive brief
Oracle Platform Security for Java is a core security component of Oracle Fusion Middleware used to manage authentication and authorization for enterprise applications. A vulnerability in the Centralized Thirdparty Jars component allows a low-privileged local user on the server to escalate privileges and take over the entire Platform Security service, potentially compromising all applications that depend on it for access control.
Technical details
The vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java versions 12.2.1.4.0 and 14.1.2.0.0. It is a local privilege escalation flaw requiring low privileges and local logon to the infrastructure where the product executes, with no user interaction required. A successful exploit allows a local attacker to completely compromise the Oracle Platform Security for Java service, gaining full control over confidentiality, integrity, and availability of the security framework. The CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates local attack vector, low complexity, and low privilege requirements with high impact across all security dimensions.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed