Impact
A vulnerability in Oracle JDeveloper’s Data Visualization Tools allows an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data and to insert or delete data that the JDeveloper application exposes. The primary impact is a high confidentiality compromise of data and potential tampering with it.
Affected Systems
Affected versions are Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a moderate‑to‑high severity vulnerability. The EPSS score of less than 1% suggests a low current exploitation likelihood, and the vulnerability is not listed in CISA KEV. An unauthenticated attacker with network access via HTTP can exploit the flaw to read and modify data exposed by the Data Visualization Tools component. The Scope: Changed vector means that successful exploitation could also affect other components or products that rely on the compromised data, potentially expanding the impact beyond the Oracle JDeveloper installation.
OpenCVE Enrichment