Impact
Oracle JDeveloper contains a local authorization bypass flaw in its ADF Faces component (CWE-200), allowing an attacker with low‑privileged access to the host to read or manipulate data exposed by the application. The vulnerability does not require network interaction and achieves a confidentiality compromise, potentially affecting all data that JDeveloper can access. Because the flaw can cause a scope change, compromising one installation may allow access to related Oracle services.
Affected Systems
Oracle JDeveloper version 12.2.1.4.0 and 14.1.2.0.0 from Oracle Corporation are affected. These releases are actively supported and can be identified via the supplied CPE strings. The flaw exists in the ADF Faces component of the product.
Risk and Exploitability
CVSS 6.5, EPSS <1%. Attack requires local access (AV:L) and low privileges (PR:L). The flaw is not listed in CISA KEV but could be exploited by someone who already has a local account, allowing them to read all JDeveloper‑exposed data and potentially impact other Oracle services through a scope change. The low EPSS score indicates a low likelihood of widespread exploitation in the wild.
OpenCVE Enrichment