What is CVE-2026-60373?
This vulnerability exists in the Oracle Platform Security for Java product within Oracle Fusion Middleware (Centralized Thirdparty Jars component) and can be easily exploited over a network via HTTP. Affected versions 12.2.1.4.0 and 14.1.2.0.0 allow a low-privileged remote attacker to compromise the system. Applying the upcoming security update from Oracle is recommended.
Azərbaycanca: Bu boşluq Oracle Fusion Middleware-in Platform Security for Java məhsulunda (Centralized Thirdparty Jars komponenti) aşkarlanıb və şəbəkə üzərindən HTTP ilə asanlıqla istismar edilə bilər. 12.2.1.4.0 və 14.1.2.0.0 versiyaları təsirlənir, aşağı səlahiyyətli uzaqdan hücumçuya imkan yaradır. Təsirlənən sistemlərdə Oracle-ın yayımlayacağı təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Oracle
FAQ2
Which Oracle product is affected by CVE-2026-60373?
CVE-2026-60373 affects the Platform Security for Java product within Oracle Fusion Middleware, specifically the Centralized Thirdparty Jars component.
What level of access does an attacker need to exploit CVE-2026-60373?
To exploit this vulnerability, an attacker requires low-privileged remote access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.