Executive brief
Oracle Platform Security for Java is a security component of Oracle Fusion Middleware that manages authentication and authorization across enterprise applications. An unauthenticated attacker can exploit a vulnerability in third-party libraries to gain complete control over this security component, potentially allowing takeover of authentication systems and compromise of all connected applications and their data.
Technical details
A difficult-to-exploit vulnerability exists in the Centralized Thirdparty Jars component of Oracle Platform Security for Java. The vulnerability allows an unauthenticated attacker with network access to send a specially crafted HTTP request to compromise the affected system. Successful exploitation results in complete system takeover with high impact to confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Patch availability status is not confirmed from the provided advisory text.
Affected products
- Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed