ZeroHour

CVE-2026-82994

moderate

Unauthenticated LDAP-Reachable Takeover in Oracle Platform Security for Java

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Oracle Platform Security for Java (OPSS), a component of Oracle Fusion Middleware, contains a critical flaw in its Centralized Thirdparty Jars component affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated remote attacker who can reach the product over LDAP can exploit the vulnerability with low complexity and no user interaction or privileges required. A successful attack results in a complete takeover of Oracle Platform Security for Java, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8). Organizations running the affected Fusion Middleware releases, particularly those with LDAP listeners reachable from untrusted networks, are at risk. There is no evidence of in-the-wild exploitation and no public proof-of-concept is known, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that remediates this CVE to installations of Oracle Platform Security for Java 12.2.1.4.0 and 14.1.2.0.0 as soon as the fix is available. Until patched, restrict network access so LDAP listeners and Fusion Middleware administrative endpoints are not reachable from untrusted or internet-facing networks. Review LDAP and middleware logs for unauthenticated or anomalous bind/query activity against OPSS endpoints and monitor Oracle's advisories for updates.

Affected
Oracle Platform Security for Java (Oracle Fusion Middleware, component: Centralized Thirdparty Jars)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
moderate≈ thousands to low tens of thousands of enterprise Fusion Middleware deployments (estimate) — Oracle Fusion Middleware/WebLogic is enterprise software with a large but predominantly internally deployed install base, and public internet scans typically show on the order of tens of thousands of exposed WebLogic-related hosts, of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.