Impact
A flaw exists in the ADF Shared Components of Oracle JDeveloper that allows an attacker who can access the application over HTTP to create, delete or modify critical data without appropriate authorization. The vulnerability can also result in application hangs or repeated crashes, leading to a denial of service. The impact spans integrity and availability because unauthorized changes can operation.
Affected Systems
Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The flaw resides in the Oracle Fusion Middleware, and only the specified releases contain the vulnerability.
Risk and Exploitability
The CVSS 3. indicates high severity with significant integrity and availability impact. The EPSS score of less than 1% suggests a very low probability of exploitation. Since the vulnerability is not listed catalog, it is not known to be actively exploited. Attacks would require network access to the JDeveloper HTTP interface and may be performed by a low-privileged user; therefore the likely attack vector is remote over HTTP.
OpenCVE Enrichment