Oracle ships restricted-use Java SE rights with more than 100 products, and buyers routinely pay a $15-per-employee subscription for JVMs those rights already cover
The Java SE bundled with WebLogic, Oracle Database, E-Business Suite, PeopleSoft, and JD Edwards is licensed to run those products and nothing else, but it is licensed. Because the Universal Subscription is priced on total employee headcount rather than installs, mapping these entitlements will not cut the invoice by itself; it cuts the compliance gap Oracle uses to justify why you need the subscription at all. The move is to document every restricted-use JVM before the sizing conversation, not after the audit letter.
Prepared by Redress Compliance · August 29, 2026 · Oracle Java advisory. Audit-defense and renewal engagements, 2023 to 2026.
Executive summary
Oracle publishes a list of over 100 products that carry a Java SE restricted-use entitlement, and most buyers can name three of them.
The authoritative source is the "Entitled Products and Restricted Use Licenses" table inside the Licensing Information User Manual for each Java SE version, and it is the document to put in front of an Oracle LMS reviewer rather than a vendor slide.
The entitlement is scoped to the host product, not the host machine, which is where 90 percent of the leakage occurs.
Oracle's WebLogic wording is explicit: Java SE and all associated components are restricted for use with WebLogic Server, Oracle Containers for J2EE, and Coherence, so a monitoring agent or batch script on the same box using that same JDK sits outside the right.
Mapping entitlements does not reduce a Universal Subscription invoice, because the metric is employee headcount, not installs.
A 5,000-employee company with Java on 40 servers pays roughly $630,000 per year at list, about $15,750 per server, whether it runs 40 JVMs or 400, so the value of entitlement mapping is in avoiding the subscription entirely or shrinking the residual population you concede.
Each Licensing Information User Manual covers only its own Java SE version, so an entitlement proven for Java SE 8 does not automatically survive an upgrade to 17 or 21.
Independently patching or upgrading the bundled JDK is the single most common way buyers convert a covered install into an unlicensed one, and Oracle's download telemetry sees it.
What a restricted-use Java right actually grants, product by product
The entitlement you are looking for is not in your ordering document. It lives in the "Entitled Products and Restricted Use Licenses" table inside Oracle's Licensing Information User Manual (LIUM) for each Java SE version, and Oracle publishes current editions for Java SE 8, 11, 25, and 26.
The grant is narrow by design: the Java SE shipped with an Oracle product may be used to run that product and its own components, and nothing else. It is not a general-purpose Java license. Two structural details do most of the damage in audits.
First, the entitlement varies by edition of the entitling product, not just by product family, so a WebLogic Standard shop and a WebLogic Suite shop hold materially different rights.
Second, each LIUM explicitly warns that it covers only that version's entitlements and that other Java SE versions may carry different restrictions. A right you hold on JDK 8 under PeopleTools does not automatically travel to a JDK 17 install you patched in yourself.
Oracle has published a list of entitling products running to over 100 items, which is why buyers who have never read the LIUM routinely underestimate how much of their JVM estate is already covered.
| Entitling product | What the Java right covers | Edition nuance | What it excludes |
|---|---|---|---|
| WebLogic Server Standard Edition | Java SE (JDK including JavaFX SDK, JRE, JavaFX Runtime, JRockit JDK) on JVMs running WebLogic | Base Java SE only, no Advanced tooling | Any JVM not running WebLogic Server |
| WebLogic Server Enterprise Edition | Java SE Advanced, restricted to WebLogic Server | Adds Advanced (Mission Control, Flight Recorder) but scope stays WebLogic | Advanced features used on non-WebLogic JVMs |
| WebLogic Suite | Java SE Suite (Java SE Advanced plus JRockit Real Time), restricted to WebLogic Server, OC4J, and Coherence | Broadest of the three, plus client access to Suite components | Standalone Java applications on the same host |
| Oracle Database | Embedded JVM for database functionality such as Java stored procedures | Included in the Database license itself | Application-tier JVMs, middleware, agents on the DB server |
| E-Business Suite | Oracle Forms, OAF pages, and other Java components inside EBS, including client JRE when users launch Forms | Client-side JRE is covered, an unusual and valuable inclusion | Custom standalone Java applications, even if EBS-adjacent |
| PeopleSoft | Java SE 8 runtime bundled with PeopleTools: app server, batch scheduler, web and process scheduler servers | Version-locked to the runtime PeopleTools ships | Independently upgraded JDKs, non-PeopleSoft workloads |
| JD Edwards EnterpriseOne | Java SE for running the JD Edwards ERP system | Restricted-use, same pattern as PeopleSoft | Use outside JD Edwards, or JDK upgraded independently of the product |
| Oracle Coherence | Described by Oracle as a full-use Java SE license | The notable exception: rights extend beyond Coherence components | Verify against your own LIUM version before relying on it |
| GlassFish (commercial), SQL Developer, Forms and Reports, Internet Application Server | Java SE to run the named product | Legacy stacks, often undocumented internally | Anything the product does not itself execute |
The load-bearing sentence is Oracle's own, from the Fusion Middleware licensing documentation: "Oracle Java SE and all components associated with it are restricted for use with WebLogic Server, Oracle Containers for J2EE and Coherence.
Java SE is included with WebLogic Suite for the sole purpose of enabling client applications to access WebLogic Suite components." Read what that clause actually does. It scopes the right to a workload, not to a machine, not to a server, and not to a JDK installation path.
Two JVMs of identical version on the same host, one running WebLogic and one running an internally built scheduler, are licensed and unlicensed respectively.
That is why LMS closing arguments almost never dispute that you hold entitlements. They dispute the boundary.
Your defensive work is therefore not "prove we own WebLogic," it is "prove which specific JVM processes serve which product," and that evidence has to be built from process inventories, not from purchase records.
Buyers wrestling with this on middleware refresh projects should read the Java SE bill hiding inside your WebLogic migration before signing anything.
Why entitlement mapping does not lower an employee-metric invoice, and what it does instead
Here is where most buyers misprice their own work. Under the Java SE Universal Subscription, Oracle's Employee metric counts all full-time, part-time, and temporary employees plus those of your agents, contractors, outsourcers, and consultants supporting internal business operations.
The quantity is determined by headcount, not by who actually uses Java, and the licensed quantity must at minimum equal that headcount as of the order effective date.
Oracle's own worked example does the arithmetic for you: 23,000 employees plus 5,000 contractors is 28,000, priced at 28,000 x $6.75 x 12 = $2,268,000 per year. If you prove that 200 of your 260 JVMs are covered by WebLogic, EBS, and Database entitlements, that invoice does not move by a dollar.
The subscription is deliberately decoupled from deployment, which is precisely why entitlement mapping delivers zero value once you have signed and enormous value before you do.
The return sits in three places. First, staying off the subscription entirely: if entitlement mapping plus OpenJDK migration reduces your unlicensed Oracle JDK population to zero, there is no compliance basis for the sales conversation at all, and the $2.27 million question never gets asked.
Second, defending a legacy processor or Named User Plus renewal, where quantities are tied to actual deployment and every covered JVM directly reduces the count Oracle can price. Third, shrinking the residual unlicensed population that Oracle uses as the lever.
In our audit-defense work, the negotiation almost never turns on the total estate; it turns on the handful of JVMs the customer cannot account for, because that gap is what converts a technical discussion into a commercial one.
Sequence matters more than thoroughness here. Mapping done after an audit letter is evidence you assemble under time pressure against a counterparty who already holds telemetry. Mapping done before sizing is leverage you control.
Build the inventory, tie each JVM to an entitling product and LIUM version, and treat the leftover as your real exposure. Then decide whether the remainder justifies a subscription at all, or whether defending it without overpaying is the cheaper path.
Defend an Oracle Java audit without overpaying
Oracle now audits Java SE on employee count, not installs, which can multiply the bill several times over. How to defend the notice and exit to OpenJDK.
Get the white paper →The entitlement is a right, not a defense: why Oracle wins the shared-host argument
Read the restricted-use language the way Oracle's LMS team reads it, not the way a procurement deck summarizes it.
The load-bearing sentence in the Fusion Middleware licensing documentation is this: "Oracle Java SE and all components associated with it are restricted for use with WebLogic Server, Oracle Containers for J2EE and Coherence.
Java SE is included with WebLogic Suite for the sole purpose of enabling client applications to access WebLogic Suite components." That is not a grant of a JVM on a server. It is a grant of a JVM for a purpose.
The moment anything on that host consumes the same runtime for a purpose outside the enumerated product set, the grant does not stretch to cover it, and the install reverts to standard Java SE terms.
Oracle publishes the entitlement list in the Licensing Information User Manual openly, across editions for Java SE 8, 11, 25 and 26, precisely because publication costs the vendor nothing.
The rights are drafted narrowly enough that they rarely survive contact with a production host that has been running for five years.
The asymmetry is the whole game. To rely on a restricted-use entitlement in an audit, you have to demonstrate that every process invoking that JDK belongs to the entitling product. Oracle has to find one that does not.
On a WebLogic box that is also running a Dynatrace or AppDynamics agent, a Jenkins build worker, a Kafka client, a vendor-supplied SFTP utility, or a shell-scheduled batch job someone wrote in 2019, the burden falls entirely on you and the evidence is scattered across process tables, cron entries.
And the memory of people who left.
In twenty-five years of running these arguments, I have never seen a buyer win a shared-host dispute on documentation alone. Buyers win by removing the shared workload before the conversation, or by conceding the host and pricing the rest properly.
Version scoping is the second trap and the one that catches technically competent estates. Each LIUM edition warns explicitly that it covers only that version's entitlement, and that other Java SE versions may carry different restrictions and entitlements.
A PeopleSoft deployment that bundles Java SE 8 with PeopleTools carries an entitlement scoped to what PeopleTools shipped. If an infrastructure team independently moves that host to JDK 17 because a security scanner flagged the old runtime, the resulting install is not an upgraded entitled JVM.
It is a new, separately licensable Oracle Java SE install that no product entitlement covers. The same applies to patching outside the host product's own update stream. The engineering instinct to stay current is precisely the behavior that converts a covered runtime into an exposed one.
Then there is visibility. Oracle does not need to guess at any of this, because the acquisition path leaves a record.
Downloads from Oracle's site under an SSO account, and update requests hitting Oracle's patch infrastructure, generate telemetry that ties a company domain to specific JDK builds on specific dates.
We cover the mechanics in detail in our analysis of what Oracle already knows from Java telemetry, but the negotiation consequence is simple: the sales team frequently opens the conversation with a list of your own downloads.
An entitlement argument that depends on nobody noticing a JDK 17 pull in March is not an argument.
There is exactly one place where the asymmetry inverts, and it is worth knowing cold. Oracle Coherence is documented as carrying a full-use Java SE license, entitling use beyond Coherence components themselves. Every other bundled entitlement in the catalogue is restricted.
If you hold Coherence, the burden of proof reverses on those hosts: Oracle would have to argue away a full-use grant it published. That single line is often worth more in a sizing conversation than a hundred mapped WebLogic JVMs, and most buyers do not know they hold it.
The conclusion follows directly. Restricted-use rights are a poor audit shield because they are conditional, version-bound, and rebuttable by a single stray process. They are an excellent sizing argument because at the negotiating table nobody is adjudicating anything.
You are establishing which portion of the estate Oracle has no legitimate claim over, before Oracle has built a compliance narrative around it. The same fact carries far more weight in September, presented as your own inventory, than it does in March, presented as a response to an LMS finding.
Use the entitlement list to shape the deal, not to survive the audit.
The four ways buyers void an entitlement they already had
Four failure modes account for nearly everything we see. Each has a specific evidentiary fingerprint that Oracle looks for, and each is checkable before anyone else checks it for you.
- Shared WebLogic hosts. The WebLogic entitlement covers JVMs running WebLogic, OC4J and Coherence, nothing else. Oracle looks for monitoring agents with their own java invocation, cron or Autosys batch jobs, and standalone JARs launched from the same
$JAVA_HOME. Check by running a full process listing during peak and off-peak windows and mapping every PID back to a product, not by trusting the deployment diagram. - Independent upgrades and out-of-band patching. The entitled runtime is the one the product ships and updates. A JDK moved forward by the infrastructure team, or patched from Oracle's site rather than through the host product's update stream, is a new install outside the grant. Oracle looks at download records against your SSO domain and at build strings that do not match the certified version for the installed product release.
- EBS and PeopleSoft JDKs used for custom code. The EBS entitlement covers Forms, OAF pages and other Java components inside the EBS environment, including client-side JRE for Forms launches. It does not cover custom standalone applications. Oracle looks for in-house JARs and integration utilities running under the ERP-supplied runtime, which is exactly where over-eager developers put them because the JDK was already there.
- Copied binaries. A bundled JDK tarred up and moved to a host that does not run the entitling product carries no rights at all. Oracle looks for identical build strings and install paths on machines with no corresponding product license, and file timestamps that betray the copy date. This is the most common finding in estates where Java hides inside third-party stacks.
Evidence base: what we see in audit files and sizing reviews
Across Oracle Java engagements the same four gaps repeat, and none of them are exotic. First, the buyer cannot produce the Licensing Information User Manual edition that matches the Java version actually deployed.
They hand over a printout of the JDK 11 entitled-products table while the estate runs JDK 8u391 and JDK 17, and every LIUM carries the warning that it covers only that version's entitlement and that other Java SE versions may have different restrictions and entitlements.
That single mismatch converts a defensible position into a conversation about Oracle's data. Second, WebLogic hosts almost never run WebLogic alone.
In our review work these boxes typically carry several additional Java processes, monitoring agents, deployment tooling, scripts, third-party middleware.
And each one sits outside the restriction Oracle wrote in plain language: Java SE and all components associated with it are restricted for use with WebLogic Server, Oracle Containers for J2EE and Coherence.
Third, E-Business Suite estates rarely document client-side JRE coverage. The entitlement covers the JRE on user machines when they launch Forms, but nobody has a list of which desktops that describes, so the entire desktop population becomes contested.
Fourth, legacy perpetual Java SE Advanced holdings show up in the paperwork and buyers assume they offset the subscription. They do not. They provide audit cover and migration runway, and they earn zero credit against the Universal Subscription price.
Oracle's published entitled-products list runs to over 100 products, most of which buyers never map before sizing.
Perpetual holdings survive as audit cover and migration runway, but reduce the employee-metric invoice by nothing.
Two caveats we apply to our own files. Oracle's Java SE Universal Subscription FAQ is not a contractual document, so nothing in it survives contact with an LMS reviewer who prefers the ordering document.
And single-source claims deserve verification before you build a position on them: the widely repeated assertion that Oracle Coherence carries a full-use Java SE license rather than a restricted one is the clearest example.
If that exception matters to your estate, pull the current LIUM for your deployed Java version and confirm the wording yourself before you put it in a response letter. The same discipline applies to any entitlement claim sourced from a blog, a partner deck, or an Oracle sales email.
What you can evidence from the LIUM and your ordering documents is leverage. What you quote from secondary sources is an opening for Oracle to reset the discussion, and the audit defence work we do starts by separating those two categories.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
Your first five moves
- Pull the LIUM for every deployed Java SE version, not just the newest, and extract the Entitled Products and Restricted Use Licenses table from each one, because JDK 8, 11, 17, and 25 editions differ and Oracle will hold you to the version you actually run.
- Inventory every Oracle JDK install and map each to a named entitling product or flag it, using the ordering document that granted the entitlement as the evidence, so the output is a two-column list of covered installs and exposed installs rather than a spreadsheet of hostnames.
- Run a process-level scan on WebLogic, EBS, PeopleSoft, and JD Edwards hosts, not a filesystem scan, because the restriction is about what the JVM executes, and a monitoring agent or a batch script running on the same host is the exposure Oracle will price, as covered in our analysis of the Java SE coupling inside WebLogic estates.
- Freeze independent JDK patching immediately and route every update through the host product's patch stream, since patching a bundled JDK outside the entitling product's channel is the fastest way to convert a restricted-use right into a full-use liability that nobody approved.
- Put the documented entitled population in writing before any Universal Subscription sizing call, naming the products, the LIUM editions, and the install counts, because once Oracle has framed your estate as unlicensed the conversation is about employee bands rather than about which JVMs were covered all along.
Frequently asked questions
Does WebLogic include a free Java SE license?
All three WebLogic editions include a Java SE entitlement: Standard Edition includes Java SE, Enterprise Edition includes Java SE Advanced, and WebLogic Suite includes Java SE Suite. All three are restricted-use.
Oracle's wording limits the right to WebLogic Server, Oracle Containers for J2EE, and Coherence, so the JVM running WebLogic is covered and any other Java process on the same host is not.
Does Oracle Database cover Java on the database server?
Oracle Database includes an embedded JVM for stored procedures and similar in-database Java functionality, and the right to use Java for that purpose is included in the database license.
It does not extend to a separately installed Oracle JDK on the same server used by scripts, agents, or middleware. Treat the embedded JVM and a standalone JDK install as two different licensing questions.
Can I use the JDK that shipped with E-Business Suite for a custom application?
No. The EBS entitlement covers running Oracle Forms, OAF pages, and other Java components within the EBS environment, including the client-side JRE when users launch Forms.
A custom standalone Java application falls outside that scope and needs its own Java SE entitlement, even if it runs on the same server and uses the same JDK binary.
Does upgrading the bundled JDK break my restricted-use right?
It can. Each Licensing Information User Manual covers only one Java SE version and warns that other versions may carry different restrictions and entitlements.
If you patch or upgrade the JDK independently rather than through the host product's certified update stream, you may be running a version your entitlement does not name. Route all bundled JDK updates through the host product's patch stream and document the version lineage.
Will mapping my restricted-use entitlements reduce a Java SE Universal Subscription quote?
Not directly. The Universal Subscription is priced on total employee headcount including agents, contractors, outsourcers, and consultants, not on the number of installs, so a 5,000-employee company pays roughly $630,000 per year at list whether it runs 40 JVMs or 400.
Entitlement mapping matters because it shrinks the unlicensed population Oracle uses to argue you need the subscription in the first place.
Which Oracle products carry a Java SE entitlement?
Oracle has published a list running to more than 100 products.
The commonly relevant ones are WebLogic Server (all editions), Oracle Database, E-Business Suite, PeopleSoft, JD Edwards EnterpriseOne, Coherence, commercial GlassFish Server, SQL Developer, Oracle Forms and Reports, and Internet Application Server.
Confirm each against the Entitled Products and Restricted Use Licenses table in the LIUM matching your deployed Java version.
Is Coherence really a full-use Java SE license?
Some sources describe Coherence as uniquely granting full-use Java SE rights extending beyond Coherence components, which would make it an exception to the restricted-use pattern.
The commercial consequence is large enough that you should verify it against the current Licensing Information User Manual for your Java version before relying on it in a negotiation or an audit response. Do not build a position on a single secondary source.