CVE-2026-60629: High severity Oracle Oracle JDeveloper vulnerability
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Data Visualization Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. While the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data as well as unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle JDeveloper (Oracle Fusion Middleware - Data Visualization Tools)to a version that resolves this vulnerability.Fixed in 12.2.1.4.0 - Upgrade
Upgrade
Oracle JDeveloper (Oracle Fusion Middleware - Data Visualization Tools)to a version that resolves this vulnerability.Fixed in 14.1.2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60629?
The severity of CVE-2026-60629 is rated high with a score of 7.5.
What software is affected by CVE-2026-60629?
CVE-2026-60629 affects the Oracle JDeveloper product within the Oracle Fusion Middleware.
How do I fix CVE-2026-60629?
To fix CVE-2026-60629, you should apply the latest security patches provided by Oracle for your affected version.
Can CVE-2026-60629 be exploited remotely?
Yes, CVE-2026-60629 can be exploited remotely by an unauthenticated attacker with network access via HTTP.
What versions of Oracle JDeveloper are vulnerable to CVE-2026-60629?
The vulnerable versions of Oracle JDeveloper associated with CVE-2026-60629 are 12.2.1.4.0 and 14.1.2.0.0.