Executive brief
Oracle JDeveloper, a development environment used for building Java applications, contains a security flaw in its Security Framework component. An unauthorized person can exploit this over the network to gain access to sensitive information. This could lead to the exposure of critical business data or intellectual property stored within the development environment.
Technical details
A vulnerability exists in the Security Framework component of Oracle JDeveloper (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to bypass confidentiality controls, resulting in unauthorized access to critical data or complete access to all data accessible by the JDeveloper instance. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high confidentiality impact with no impact on integrity or availability.
Affected products
- Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory