CVE-2022-21445
KEVlargeUnauthenticated Deserialization Flaw in Oracle ADF Faces Enables Application Takeover
CISA: Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
Oracle ADF Faces, the user-interface component of Oracle Application Development Framework (ADF) within Oracle Fusion Middleware, is vulnerable to deserialization of untrusted data (CWE-502) in versions 12.2.1.3.0 and 12.2.1.4.0. The flaw is easily exploitable: an unauthenticated attacker with network access sends malicious serialized data over HTTP, requiring no credentials, privileges, or user interaction. Successful attacks can result in takeover of the ADF deployment, with high confidentiality, integrity, and availability impacts reflected in the critical CVSS 3.1 score of 9.8. Organizations running ADF-based applications, typically built with Oracle JDeveloper and deployed as part of Oracle Fusion Middleware, are affected on the listed versions. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2024-09-18, confirming exploitation in the wild; EPSS assigns a 62.5% probability of exploitation within 30 days (99th percentile), while public PoC code and ransomware association are not documented.
What to do: Inventory Oracle Fusion Middleware and JDeveloper-built deployments for ADF Faces versions 12.2.1.3.0 and 12.2.1.4.0 and apply the current Oracle Critical Patch Update as directed by the Fusion Middleware Patch Advisor. Prioritize internet-exposed ADF applications given confirmed in-the-wild exploitation, and per the CISA KEV required action, apply vendor mitigations or discontinue use if mitigations are unavailable. Until patched, restrict HTTP access to ADF Faces endpoints.
| Oracle Application Development Framework (ADF) - ADF Faces component, Oracle Fusion Middleware (distributed via Oracle J | 12.2.1.3.0 and 12.2.1.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middleware Patch Advisor for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Affected
- Oracle ADF Faces
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- oracle
- Products
- application development framework
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H