Impact
A flaw in the Resource Catalog Services component of Oracle JDeveloper allows an attacker with low privileges to communicate over HTTP and achieve a full compromise of the JDeveloper instance, leading to loss of confidentiality, integrity, and availability. The vulnerability is easily exploitable from the network and requires no user interaction beyond normal HTTP requests. Successful exploitation enables an attacker to take control of the JDeveloper environment.
Affected Systems
Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware and are supported under the indicated product lines.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity, but the EPSS score of less than 1 % suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, further indicating limited active exploitation. The attack can be launched via standard HTTP network access and only requires low‑privileged credentials, resulting in full compromise of the JDeveloper instance when successful.
OpenCVE Enrichment