Impact
The vulnerability lies in Oracle JDeveloper's ADF Faces component and allows an unauthenticated attacker with HTTP network access to read a subset of data exposed by the application. This is a CWE-200 weakness, Information Exposure. Based on the description, it is inferred that the flaw manifests as improper access control that permits data retrieval without prior authentication.
Affected Systems
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 are affected, as specified in the Oracle CPU July 2026 alert.
Risk and Exploitability
With a CVSS base score of 3.7 and an EPSS score of less than 1%, exploitation is considered low probability. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is a remote attacker sending an HTTP request to the vulnerable JDeveloper instance; successful exploitation provides read access to protected data without authentication, compromising confidentiality but not integrity or availability.
OpenCVE Enrichment