Junglewise Threat Intelligence

CVE-2026-60349: Oracle JDeveloper information disclosure in Java Business Objects

CVE-2026-60349 · Severity: medium · CVSS 5.9 · Published 2026-07-21

Technologies: Oracle Jdeveloper. Vendors: Oracle.

Executive brief

Oracle JDeveloper, a development environment for building Java-based applications, contains a security vulnerability in its Java Business Objects component. A low-privileged attacker could exploit this flaw to gain unauthorized access to sensitive application data or cause a partial service disruption. While the attack is difficult to execute, it could lead to a significant breach of confidentiality for data managed within the development environment.

Technical details

A vulnerability in the Java Business Objects component of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0) allows a low-privileged attacker with network access via HTTP to compromise the system. The vulnerability is characterized by high attack complexity, requiring specific conditions to be met for successful exploitation. If exploited, an attacker can achieve unauthorized access to critical data or all data accessible by JDeveloper, as well as cause a partial denial of service (DoS). The CVSS vector indicates a confidentiality impact of 'High' and an availability impact of 'Low', with no impact on integrity.

Affected products

  • Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-60349 by Oracle.

References

Related threats