Executive brief
Oracle Fusion Middleware's Remote Diagnostic Agent component is vulnerable to privilege escalation, allowing a low-privileged user with local access to gain complete control over the affected system. This can lead to unauthorized access to sensitive business data and disruption of critical middleware services that support enterprise applications.
Technical details
This is a local privilege escalation vulnerability in the Remote Diagnostic Agent component of Oracle Middleware Common Libraries and Tools. The vulnerability requires local system access and low-level privileges to exploit, but results in complete system compromise. The attack vector is local (AV:L), with low attack complexity (AC:L) and low privilege requirements (PR:L), allowing an authenticated local attacker to escalate privileges and gain full control over the middleware infrastructure. No patch availability information is currently available.
Affected products
- Oracle Fusion Middleware 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-09-15: disclosed