CVE-2022-21445
Description
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middleware Patch Advisor for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Summary dbcve.org
A critical, easily exploitable vulnerability exists in the ADF Faces component of Oracle Application Development Framework (Fusion Middleware) versions 12.2.1.3.0 and 12.2.1.4.0, reachable by an unauthenticated remote attacker over HTTP. Successful exploitation can lead to full takeover of the Oracle ADF installation, impacting confidentiality, integrity, and availability.
Mitigation
Identify all Oracle ADF/Fusion Middleware 12.2.1.3.0 and 12.2.1.4.0 instances and apply the security patch recommended by the Oracle Fusion Middleware Patch Advisor for CVE-2022-21445, prioritizing internet-exposed systems. Additionally, restrict network access to ADF endpoints at the firewall/WAF layer and audit HTTP access logs for prior exploitation attempts.