Vulnerability record · CVE-2022-21445 · published 19 April 2022
CVE-2022-21445: Oracle ADF Faces deserialization of untrusted data
Oracle · Application Development Framework
Oracle Application Development Framework (ADF) Faces in Oracle Fusion Middleware contains a deserialization of untrusted data flaw affecting versions 12.2.1.3.0 and 12.2.1.4.0. It is reachable over HTTP without authentication and can lead to full takeover of the affected ADF component. The CVSS 3.1 base score is 9.8, and CISA added it to the Known Exploited Vulnerabilities catalog.
Description
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middleware Patch Advisor for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network-reachable takeover, active inclusion in CISA KEV and a very high EPSS score make this an urgent patching target.
What it is
Oracle Application Development Framework (ADF) Faces in Oracle Fusion Middleware contains a deserialization of untrusted data flaw affecting versions 12.2.1.3.0 and 12.2.1.4.0. It is reachable over HTTP without authentication and can lead to full takeover of the affected ADF component. The CVSS 3.1 base score is 9.8, and CISA added it to the Known Exploited Vulnerabilities catalog.
Impact
An unauthenticated attacker can achieve full compromise of the ADF component, with high confidentiality, integrity and availability impact, effectively taking over the affected application.
Attack surface
Reached over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed ADF Faces deployment on the affected versions is in scope.
Exploitation
Listed in CISA KEV since 2024-09-18 with a 2024-10-09 remediation due date, indicating known exploitation in the wild. EPSS 30-day probability is 0.62478 (99.1st percentile), and no ransomware campaign use is documented.
What to do
- Apply the Oracle April 2022 Critical Patch Update (cpuapr2022) for ADF 12.2.1.3.0 and 12.2.1.4.0, or follow the Fusion Middleware Patch Advisor guidance.
- If patching is not immediately possible, restrict network access to ADF Faces endpoints and discontinue use if no mitigation is available, per CISA required action.
- Place ADF deployments behind authentication-aware reverse proxies or WAF rules that block untrusted serialized payloads where feasible.
- Inventory all ADF Faces instances, including those bundled via Oracle JDeveloper, to confirm which hosts run the affected versions.
- Monitor for and remove unnecessary external exposure of ADF Faces HTTP endpoints.
Detection
- Inspect HTTP request bodies to ADF Faces endpoints for serialized Java object streams (for example base64 or binary markers such as rO0AB or AC ED 00 05).
- Alert on anomalous POST traffic to ADF Faces URLs from unauthenticated or unfamiliar source IPs.
- Review application and web server logs for deserialization errors, class-loading anomalies or unexpected process spawning on ADF hosts.
- Correlate ADF host activity with outbound connections or new child processes that may indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-21445 to the Known Exploited Vulnerabilities catalog on 18 September 2024 as "Oracle ADF Faces Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 October 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2022.html | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2022.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-21445 | US Government Resource |
Track CVE-2022-21445 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21445), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.