Impact
The vulnerability resides in the Resource Catalog Services component of Oracle JDeveloper, where an unauthenticated attacker can send specially crafted HTTP requests over the network. If successfully exploited, the attacker can read sensitive configuration data, gain full access to all data exposed by JDeveloper, and induce a partial denial of service, lowering system availability. This weakness is effectively an improper access control flaw that permits unauthorized privileges without authentication.
Affected Systems
Oracle JDeveloper products from Oracle Corporation, specifically version 12.2.1.4.0 and 14.1.2.0.0, are impacted. No other supported versions were identified in the advisory.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 8.2, indicating high confidentiality impact and moderate availability impact. The EPSS score is less than 1 percent, suggesting that, as of the analysis, the likelihood of exploitation in the wild is low. However, the advisory lists the vulnerability as exploitable by unauthenticated users over HTTP, meaning an attacker with network access to the JDeveloper instance could potentially compromise data confidentiality and disrupt services. The vulnerability is not currently listed in the CISA KEV catalog, but its high severity warrants prompt remediation.
OpenCVE Enrichment