cbcvebase.

Oracle Jdeveloper vulnerabilities

25 known vulnerabilities affecting oracle/jdeveloper.

Total CVEs
25
CISA KEV
0
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL8HIGH5MEDIUM8LOW4

Vulnerabilities

Page 2 of 2
CVE-2005-2291P4MEDIUMCVSS 4.6v9.0.4v9.0.5+1 more2005-07-18
CVE-2005-2291 [MEDIUM] CVE-2005-2291: Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when startin Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.
nvd
CVE-2019-2899P4LOWCVSS 2.4v11.1.1.9.0v11.1.2.4.0+2 more2019-10-16
CVE-2019-2899 [LOW] CVE-2019-2899: Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Supported versions that are affected are 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks require human int
nvd
CVE-2005-2292P4LOWCVSS 2.1v9.0.4v9.0.5+1 more2005-07-18
CVE-2005-2292 [LOW] CVE-2005-2292: Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.
nvd
CVE-2008-2623P4LOWCVSS 2.1v10.1.2.32009-01-14
CVE-2008-2623 [LOW] CVE-2008-2623: Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.3 a Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.3 allows local users to affect confidentiality via unknown vectors.
nvd
CVE-2008-2588P4LOWCVSS 2.1v10.1.2.22008-10-14
CVE-2008-2588 [LOW] CVE-2008-2588: Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 a Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 allows local users to affect confidentiality via unknown vectors.
nvd
Oracle Jdeveloper vulnerabilities | cvebase