Description
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data as well as unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle JDeveloper’s Data Visualization Tools allows an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data and to insert or delete data that the JDeveloper application exposes. The primary impact is a high confidentiality compromise of data and potential tampering with it.

Affected Systems

Affected versions are Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a moderate‑to‑high severity vulnerability. The EPSS score of less than 1% suggests a low current exploitation likelihood, and the vulnerability is not listed in CISA KEV. An unauthenticated attacker with network access via HTTP can exploit the flaw to read and modify data exposed by the Data Visualization Tools component. The Scope: Changed vector means that successful exploitation could also affect other components or products that rely on the compromised data, potentially expanding the impact beyond the Oracle JDeveloper installation.

Generated by OpenCVE AI on August 4, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle JDeveloper patch or update to a version that includes the fix for the Data Visualization Tools component.
  • Restrict network access to the HTTP interface using firewalls or VPNs so that only trusted hosts can reach it.
  • Review and enforce stricter access controls on visualization features, disabling unused components or restricting them to authorized users only.

Generated by OpenCVE AI on August 4, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Access via HTTP in Oracle JDeveloper Data Visualization Tools

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Access via HTTP in Oracle JDeveloper Data Visualization Tools

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Data Access in Oracle JDeveloper Data Visualization Tools

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based Data Access in Oracle JDeveloper Data Visualization Tools
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data as well as unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle jdeveloper
CPEs cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jdeveloper
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Jdeveloper
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:38:07.940Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60629

cve-icon Vulnrichment

Updated: 2026-07-27T12:38:03.677Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses