Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle JDeveloper, part of Oracle Fusion Middleware, contains a flaw in the ADF Faces component that allows an attacker with low privileges and network connectivity over HTTP to read limited application data. The vulnerability is an information exposure and an improper authorization weakness, as indicated by CWE-284. Successful exploitation permits confidential data to be read but does not affect integrity or availability.

Affected Systems

The affected product is Oracle JDeveloper. Supported versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. No additional sub‑versions are specified. The products are identified by CPE strings for Oracle JDeveloper at the indicated versions.

Risk and Exploitability

The CVSS base score of 3.1 reflects limited confidentiality impact, and the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to send a crafted HTTP request to the JDeveloper instance. While the required privileges are low, the attacker must have network access to the application; after successful exploitation read access to a subset of application data is granted.

Generated by OpenCVE AI on August 2, 2026 at 22:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Limit HTTP access to the JDeveloper service to trusted hosts or networks, using firewalls or access‑control lists.
  • Enforce authentication and authorization on the application so that only authorized users can retrieve data.
  • Monitor network traffic and application logs for unauthorized data‑extraction requests and investigate anomalies promptly.
  • Consult Oracle's security advisory page for any vendor‑issued patch or update and apply it when available.

Generated by OpenCVE AI on August 2, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Information Exposure in Oracle JDeveloper ADF Faces Component

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Low-Privileged Read-Access Vulnerability in Oracle JDeveloper ADF Faces
Weaknesses CWE-200

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low-Privileged Read-Access Vulnerability in Oracle JDeveloper ADF Faces
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:41:16.169Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60353

cve-icon Vulnrichment

Updated: 2026-07-24T18:40:59.705Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses