CVE-2026-60354: Infoleak
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle JDeveloper (Oracle Fusion Middleware) - Data Visualization Toolsto a version that resolves this vulnerability.Fixed in 12.2.1.4.0 - Upgrade
Upgrade
Oracle JDeveloper (Oracle Fusion Middleware) - Data Visualization Toolsto a version that resolves this vulnerability.Fixed in 14.1.2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60354?
The severity of CVE-2026-60354 is low, rated at 3.7.
How do I fix CVE-2026-60354?
To fix CVE-2026-60354, update to the latest supported versions of Oracle JDeveloper.
What components are affected by CVE-2026-60354?
CVE-2026-60354 affects the Data Visualization Tools component of Oracle JDeveloper.
What does CVE-2026-60354 exploit?
CVE-2026-60354 is a difficult to exploit vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.
What versions of Oracle JDeveloper are impacted by CVE-2026-60354?
The impacted versions of Oracle JDeveloper are 12.2.1.4.0 and 14.1.2.0.0.