Executive brief
A vulnerability exists in Oracle JDeveloper, a development environment used for building enterprise applications. An attacker with basic access to the computer where the software is running can exploit this flaw to gain unauthorized access to sensitive data. This could lead to a significant breach of confidentiality, potentially affecting other integrated systems beyond JDeveloper itself.
Technical details
A vulnerability in the ADF Faces component of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0) allows for unauthorized data access. The attack vector is local, requiring the attacker to have logon credentials for the infrastructure where JDeveloper is executing. The vulnerability is characterized by a 'Scope Change' (S:C), indicating that the impact can extend beyond the security scope of JDeveloper to other components or products. Successful exploitation results in a high confidentiality impact (C:H), granting access to all JDeveloper-accessible data. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.