Impact
Oracle JDeveloper’s Data Visualization Tools contains a flaw that allows an unauthenticated attacker with network access via HTTP to read a subset of data. The vulnerability does not enable code execution, privilege‑escalation, or denial‑of‑service; it solely impacts confidentiality, reflected in a CVSS score of 3.7 and a confidentiality impact of Low.
Affected Systems
The affected products are Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score indicates a low‑severity flaw, and the EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker only needs to send unauthenticated HTTP requests to the JDeveloper instance to read data; no special privileges or device access are required.
OpenCVE Enrichment