Impact
Oracle JDeveloper, part of Oracle Fusion Middleware, contains a vulnerability in its ADF Faces component. An unauthenticated attacker can exploit the flaw over HTTP, allowing them to compromise the application. Successful exploitation can lead to unauthorized access to data stored or processed by JDeveloper, including complete access to all data exposed by the application. The weakness is a confidentiality impact, as denoted by the CVSS vector with a high impact on confidentiality but no integrity or availability impact.
Affected Systems
Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are supported by Oracle and deployable within enterprise environments. All installations of JDeveloper that expose the ADF Faces component over HTTP fall within the risk scope.
Risk and Exploitability
The CVSS base score of 5.9 reflects a moderate risk of confidentiality compromise. The EPSS score of less than 1% indicates a low probability of exploitation with current evidence. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need network access to the affected JDeveloper instance and would communicate over HTTP, but the exploitation is described as difficult, so successful attacks are unlikely without tailored effort.
OpenCVE Enrichment