Impact
Oracle JDeveloper’s ADF Shared Components contain an improper authorization flaw that allows a high‑privileged attacker with network access via HTTP to compromise the application. Successful exploitation can lead to a full takeover, giving the attacker complete confidentiality, integrity and availability control over the JDeveloper instance.
Affected Systems
Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0 are affected.
Risk and Exploitability
The CVSS 3.1 base score is 7.2, indicating high severity, and the EPSS score of less than 1% reflects a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attacks are expected to be conducted over HTTP from the network, requiring high‑privileged credentials, and can result in complete system takeover.
OpenCVE Enrichment