Record summary

CVE-2022-21445 has a selected CVSS score of 9.8 (critical). CISA lists CVE-2022-21445 in KEV.

Description

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Sep 18, 2024 · CISA
VulnCheck KEV
Listed · Oct 8, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List12.2.1.3.0affected
12.2.1.4.0affected

Default status: unknown

CVE List12.2.1.3.0affected
12.2.1.4.0affected

References

3