Junglewise Threat Intelligence

CVE-2022-21445: Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

CVE-2022-21445 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-09-18

Technologies: Oracle Jdeveloper. Vendors: Oracle.

Executive brief

Oracle ADF Faces, a component of Oracle Fusion Middleware and JDeveloper, contains a deserialization of untrusted data vulnerability. An unauthenticated remote attacker can exploit this via HTTP to achieve full system takeover and remote code execution.

Affected products

  • Oracle Application Development Framework (ADF) Faces 12.2.1.3.0, 12.2.1.4.0
  • Oracle JDeveloper 12.2.1.3.0, 12.2.1.4.0

Timeline

  • 2022-04-19: advisory: Oracle Critical Patch Update Advisory - April 2022
  • 2024-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-18: disclosed