Impact
A flaw exists in the ADF Shared Components of Oracle JDeveloper that permits an attacker with network access via HTTP to create, delete, or modify critical data without proper authorization. The vulnerability can also lead to application hangs or repeated crashes, providing a means to interrupt service availability. The flaw is a direct result of privileged access control weaknesses, allowing a low privileged attacker to alter or overwhelm data integrity and availability.
Affected Systems
Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability resides within the Oracle Fusion Middleware ADF Shared Components component and impacts only the specified releases.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity with integrity and availability impacts. The EPSS score of less than 1% shows a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over HTTP; a low privileged attacker who can reach the JDeveloper HTTP interface could exploit the lack of proper authorization checks to modify or delete data and force the application to crash.
OpenCVE Enrichment