Impact
The flaw resides in the ADF Faces component of Oracle JDeveloper, permitting attackers who can reach the server over HTTP to read, insert, update, or delete data that the application exposes; no impact on availability is reported. The vulnerability does not require authentication, thereby enabling unauthenticated users to exploit it once network access is obtained.
Affected Systems
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 are affected. The issue is part of Oracle Fusion Middleware’s ADF Faces component; no other product versions were identified as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 4.8 indicates low‑to‑moderate severity, primarily affecting confidentiality and integrity. The EPSS score is less than 1 %, implying a very low probability that the flaw will be actively exploited. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attacker must be able to reach the target over HTTP and does not need any credentials; however, the problem is described as difficult to exploit, suggesting that additional conditions (e.g., correct request formatting or specific context) may be required.
OpenCVE Enrichment