Impact
A flaw in Oracle JDeveloper's ADF Faces component allows an unauthenticated attacker to bypass authentication controls and execute arbitrary code. This results in full compromise of the application, granting the attacker complete confidentiality, integrity, and availability damage. The weakness is an authentication bypass flaw and missing authentication mechanisms, classified as CWE‑287 and CWE‑306.
Affected Systems
Oracle JDeveloper, version 12.2.1.4.0 and 14.1.2.0.0, are affected. The vulnerability applies to installations of Oracle Fusion Middleware that include these JDeveloper releases. Any environment exposing the application to HTTP traffic is potentially vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 9.8 indicates critical severity, with all three impact metrics rated high. The EPSS score is below 1%, indicating a low current exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the attack vector is network‑based via unauthenticated HTTP requests, making exploitation trivial for attackers with network access.
OpenCVE Enrichment