Impact
A local vulnerability within the Oracle JDeveloper Security Framework allows an attacker who is already logged on to JDeveloper’s host to compromise the application, resulting in loss of confidentiality, integrity, and availability of JDeveloper services. The CVSS 3.1 base score of 7.0 reflects these combined impacts. The weakness is of a type that grants the attacker broader control of the JDeveloper environment once accessed.
Affected Systems
Oracle JDeveloper 12.2.1.4.0 and 14.1.2.0.0 are known to be affected by this flaw.
Risk and Exploitability
The CVSS 3.1 base score of 7.0 indicates a high severity impact on confidentiality, integrity, and availability, reflecting moderate to high risk for the affected application. The EPSS score indicates a very low but non‑zero chance of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring the attacker to have logon access to the infrastructure where JDeveloper runs; no remote trigger is available. Given the low exploitation probability and the local nature, the primary risk is to users who can obtain local accounts, rather than a widespread, automated attack surface.
OpenCVE Enrichment