Impact
Oracle JDeveloper, part of Oracle Fusion Middleware, contains a flaw in the ADF Faces component that allows an attacker with low privileges and network connectivity over HTTP to read limited application data. The vulnerability is an information exposure and an improper authorization weakness, as indicated by CWE-284. Successful exploitation permits confidential data to be read but does not affect integrity or availability.
Affected Systems
The affected product is Oracle JDeveloper. Supported versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. No additional sub‑versions are specified. The products are identified by CPE strings for Oracle JDeveloper at the indicated versions.
Risk and Exploitability
The CVSS base score of 3.1 reflects limited confidentiality impact, and the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to send a crafted HTTP request to the JDeveloper instance. While the required privileges are low, the attacker must have network access to the application; after successful exploitation read access to a subset of application data is granted.
OpenCVE Enrichment