EXPOSURES › CVE-2022-21445
CVE-2022-21445
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data.
This vulnerability enables attackers to execute arbitrary code on systems running Oracle JDeveloper Distribution without authentication, posing a severe risk to defense-industrial-base environments relying on Oracle middleware. DIB organizations must immediately patch Oracle ADF Faces to prevent exploitation and avoid potential FCA settlements or supply-chain compromise.
Shame score — A critical RCE vulnerability in a widely used Oracle component that was actively exploited in the wild, though not zero-day.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |