CVE-2022-21445 is a critical vulnerability in Oracle Application Development Framework (ADF) versions 12.2.1.3.0 and 12.2.1.4.0, specifically impacting the ADF Faces component. This easily exploitable flaw allows an unauthenticated attacker with network access via HTTP to fully compromise the ADF instance, leading to complete takeover with high impacts on confidentiality, integrity, and availability. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog. While no public exploit code is listed for Metasploit, Nuclei, or ExploitDB, there is significant community discussion and media coverage surrounding this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.1.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:application_development_framework:12.2.1.3.0:*:*:*:*:*:*:* | ||
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:application_development_framework:12.2.1.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.