logo

CVE-2022-21445 - Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Project:Oracle

Product:ADF Faces

Date Added:2024-09-18Due Date:2024-10-09

Vulnerability Name

Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Description

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://www.oracle.com/security-alerts/cpuapr2022.html

https://nvd.nist.gov/vuln/detail/CVE-2022-21445

Related News Articles

CISA warns of actively exploited Apache HugeGraph-Server bugSeptember 20, 2024