Executive brief
Oracle JDeveloper is an integrated development environment used by enterprises to build Java applications. A vulnerability in its ADF Shared Components allows authenticated network attackers to modify or delete critical application data, or crash the development environment entirely. This could disrupt development workflows, corrupt project data, and compromise the integrity of applications under development.
Technical details
The vulnerability exists in Oracle JDeveloper's ADF Shared Components and is exploitable via HTTP by low-privileged authenticated network attackers without user interaction required. The exact vulnerability class is not explicitly stated in the advisory, but the impact encompasses both integrity (unauthorized creation, deletion, or modification of critical data) and availability (denial of service via hang or crash). The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. A patch or update is likely available from Oracle through their standard security patching process, though the reference URL to Oracle's advisory was inaccessible at time of analysis.
Affected products
- Oracle JDeveloper 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed