PT-2022-3364 · Oracle · Oracle Jdeveloper

Publicado

2022-04-19

·

Atualizado

2022-04-19

·

CVE-2022–21445

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Oracle Jdeveloper (affected versions not specified)
Description: The issue is related to the ADF Faces component of Oracle Jdeveloper, which is vulnerable to a memory corruption flaw. This flaw can be exploited by a remote attacker to execute arbitrary code or gain full control of the application using the HTTP protocol.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-04130
CVE-2022–21445

Produtos afetados

Oracle Jdeveloper