Impact
The vulnerability resides in Oracle JDeveloper’s Security Framework, allowing an unauthenticated attacker with network access over HTTP to exploit the system and extract critical data. Because no authentication is required, an attacker could bypass all built‑in security controls and obtain any data that the JDeveloper instance can access, compromising confidentiality.
Affected Systems
Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions run on Oracle Fusion Middleware.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity flaw that primarily impacts confidentiality. The EPSS score is below 1 %, suggesting that exploitation is not common today, and the vulnerability is not listed in CISA KEV. Nonetheless, the access vector is remote HTTP traffic, and the flaw is easily exploitable without authentication, making it moderately high risk for any organization that exposes JDeveloper to the network.
OpenCVE Enrichment