Executive brief
Oracle JDeveloper, a development environment used for building enterprise applications, contains a security vulnerability in its Data Visualization Tools component. An unauthenticated attacker could potentially gain unauthorized access to a limited amount of data within the application. While the risk is considered low due to the difficulty of exploitation, it could lead to minor information disclosure.
Technical details
A vulnerability exists in the Data Visualization Tools component of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw allows an unauthenticated attacker with network access via HTTP to compromise the environment. The attack is characterized by high complexity (AC:H), suggesting specific conditions must be met for successful exploitation. If successful, the attacker can achieve unauthorized read access to a subset of Oracle JDeveloper accessible data, impacting confidentiality. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-60354 was published to the NVD.