Junglewise Threat Intelligence

CVE-2017-3255: Oracle JDeveloper information disclosure in ADF Faces

CVE-2017-3255 · Severity: medium · CVSS 5.8 · Published 2017-01-27

Technologies: Oracle Jdeveloper. Vendors: Oracle.

Executive brief

A vulnerability exists in the ADF Faces component of Oracle JDeveloper, a development environment used for building enterprise applications. An unauthenticated attacker can remotely access the system over the network to view sensitive information. This could lead to the unauthorized disclosure of data and potentially impact other integrated Oracle Fusion Middleware products.

Technical details

This vulnerability (CWE-200) is located in the ADF Faces subcomponent of Oracle JDeveloper. It is classified as an information exposure flaw that can be exploited by an unauthenticated attacker via the HTTP protocol. The attack vector is network-based and requires low complexity with no user interaction. While the vulnerability resides in JDeveloper, the 'Scope' metric is changed (S:C), indicating that an exploit can impact components beyond the immediate security scope of the vulnerable software. Attackers can achieve unauthorized read access to sensitive data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle JDeveloper 11.1.1.7.0, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0, 12.2.1.2.0

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats