Skip to content
COOEY

EXPOSURES › CVE-2022-21445

CVE-2022-21445

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-21445 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildransomwaresupply-chainunpatched

Oracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data.

This vulnerability enables attackers to execute arbitrary code on systems running Oracle JDeveloper Distribution without authentication, posing a severe risk to defense-industrial-base environments relying on Oracle middleware. DIB organizations must immediately patch Oracle ADF Faces to prevent exploitation and avoid potential FCA settlements or supply-chain compromise.

Shame score — A critical RCE vulnerability in a widely used Oracle component that was actively exploited in the wild, though not zero-day.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized