Executive brief
A vulnerability exists in the Oracle Application Development Framework, a tool used by developers to build enterprise Java applications. A highly privileged attacker with existing access to the underlying server could exploit this flaw to access sensitive business data. While the impact on data confidentiality is significant, the attack is difficult to execute and requires high-level system permissions.
Technical details
This vulnerability (CWE-284) affects the Java Business Objects component of Oracle ADF. It is characterized by improper access control that can be exploited by a high-privileged attacker who already has local logon access to the infrastructure where ADF is running. The attack complexity is rated as high, suggesting specific timing or environmental conditions are required for a successful exploit. If successful, an attacker can achieve unauthorized access to all ADF-accessible data, impacting the confidentiality of the system. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle Application Development Framework (ADF) 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle via NVD and security alert.