Impact
A vulnerability in Oracle JDeveloper’s Java Business Objects component allows an attacker with low privileges and network access to the HTTP interface to read or modify any data the application is configured to expose. The flaw is categorized as CWE-200 Information Exposure and can lead to the unauthorized disclosure of critical data or full access to all data that JDeveloper can reach. Additionally, the attacker can induce a partial denial of service of the application.
Affected Systems
Oracle Corporation’s JDeveloper, specifically versions 12.2.1.4.0 and 14.1.2.0.0, are impacted. These releases are part of the Oracle Fusion Middleware stack.
Risk and Exploitability
The CVSS 3.1 base score of 5.9 indicates moderate severity, with high confidentiality impact and low availability impact. The EPSS score of less than 1 % signals a low probability of exploitation. The vulnerability is exploitable over the public internet via the HTTP interface, requires only low privilege and high attack complexity, and enables an attacker to read sensitive data or cause a partial service disruption. The vulnerability is not listed in the CISA KEV catalog, but the presence of a network‑over‑HTTP attack vector warrants careful monitoring and timely patching.
OpenCVE Enrichment