Impact
The vulnerability is an unauthenticated remote flaw in Oracle JDeveloper that allows traffic over HTTP to bypass authentication, exploiting the weakness identified as CWE-200 (Exposure of Sensitive Information). An attacker can exploit this without credentials and gain unauthorized access to any data available to JDeveloper. The CVSS 3.1 base score is 7.5, indicating a high confidentiality impact while integrity and availability are not affected. This could let a malicious actor read or export sensitive project information.
Affected Systems
The affected products are Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware. The vulnerability involves an authentication bypass over HTTP.
Risk and Exploitability
The risk is low in terms of exploitation probability, with an EPSS score below 1 %. The vulnerability is not currently listed in CISA’s KEV catalog, so no known active exploits are reported. Based on the description, it is inferred that the attacker must have network access to the JDeveloper HTTP port. Successful exploitation would allow read‑only or full data access to the developer's repositories without authentication, compromising confidentiality and potentially leading to data exfiltration or compliance issues.
OpenCVE Enrichment