Executive brief
A vulnerability exists in the Oracle Application Development Framework (ADF), a tool used by developers to build enterprise applications. A high-privileged attacker could exploit this flaw to gain full control over the framework. This could lead to a complete compromise of the applications built on this framework, potentially resulting in data theft or service disruption.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the ADF Shared Components of Oracle Fusion Middleware. It is easily exploitable by a high-privileged attacker with network access via HTTP. The flaw allows for a complete takeover of the Oracle Application Development Framework, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle Application Development Framework (ADF) 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory