CVE-2026-60345: High severity Oracle Oracle JDeveloper vulnerability
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle JDeveloper (Oracle Fusion Middleware - ADF Shared Components)to a version that resolves this vulnerability.Fixed in 12.2.1.4.0 - Upgrade
Upgrade
Oracle JDeveloper (Oracle Fusion Middleware - ADF Shared Components)to a version that resolves this vulnerability.Fixed in 14.1.2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60345?
CVE-2026-60345 has a severity rating of high at 7.2.
What can exploit CVE-2026-60345?
CVE-2026-60345 can be exploited by a high privileged attacker with network access via HTTP.
Which versions are affected by CVE-2026-60345?
The affected versions of Oracle JDeveloper by CVE-2026-60345 are 12.2.1.4.0 and 14.1.2.0.0.
What type of components does CVE-2026-60345 impact?
CVE-2026-60345 impacts the ADF Shared Components of Oracle JDeveloper.
How do I mitigate CVE-2026-60345?
To mitigate CVE-2026-60345, it is recommended to apply the relevant patches provided by Oracle.