Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in Oracle JDeveloper's ADF Faces component and allows an unauthenticated attacker with HTTP network access to read a subset of data exposed by the application. This is a CWE-200 weakness, Information Exposure. Based on the description, it is inferred that the flaw manifests as improper access control that permits data retrieval without prior authentication.

Affected Systems

Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 are affected, as specified in the Oracle CPU July 2026 alert.

Risk and Exploitability

With a CVSS base score of 3.7 and an EPSS score of less than 1%, exploitation is considered low probability. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is a remote attacker sending an HTTP request to the vulnerable JDeveloper instance; successful exploitation provides read access to protected data without authentication, compromising confidentiality but not integrity or availability.

Generated by OpenCVE AI on August 4, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the official Oracle JDeveloper security patch or upgrade to a fixed version as detailed in the Oracle CPU July 2026 alert.
  • Restrict inbound HTTP traffic to trusted networks or enforce authentication on the JDeveloper web interface.
  • Monitor application logs for anomalous data read attempts to detect unauthorized access.

Generated by OpenCVE AI on August 4, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Oracle JDeveloper ADF Faces Improper Access Control Enables Unauthenticated Data Disclosure

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Oracle JDeveloper ADF Faces Improper Access Control Enables Unauthenticated Data Disclosure

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Information Disclosure in Oracle JDeveloper ADF Faces via HTTP
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Information Disclosure in Oracle JDeveloper ADF Faces via HTTP
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:43:10.410Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60352

cve-icon Vulnrichment

Updated: 2026-07-24T18:42:42.566Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor