CVE-2022-21445 - Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Project:Oracle
Product:ADF Faces
Date Added:2024-09-18Due Date:2024-10-09
Vulnerability Name
Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Description
Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://www.oracle.com/security-alerts/cpuapr2022.html
https://nvd.nist.gov/vuln/detail/CVE-2022-21445
Related News Articles
CISA warns of actively exploited Apache HugeGraph-Server bugSeptember 20, 2024