← Vulnerability feed

Vulnerability record · CVE-2022-21445 · published 19 April 2022

CVE-2022-21445: Oracle ADF Faces deserialization of untrusted data

Oracle · Application Development Framework

Oracle Application Development Framework (ADF) Faces in Oracle Fusion Middleware contains a deserialization of untrusted data flaw affecting versions 12.2.1.3.0 and 12.2.1.4.0. It is reachable over HTTP without authentication and can lead to full takeover of the affected ADF component. The CVSS 3.1 base score is 9.8, and CISA added it to the Known Exploited Vulnerabilities catalog.

9.8 CVSS 3.1 Critical CISA KEV since 18 Sep 2024 EPSS 62% · top 0.8% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
62%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middleware Patch Advisor for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network-reachable takeover, active inclusion in CISA KEV and a very high EPSS score make this an urgent patching target.

What it is

Oracle Application Development Framework (ADF) Faces in Oracle Fusion Middleware contains a deserialization of untrusted data flaw affecting versions 12.2.1.3.0 and 12.2.1.4.0. It is reachable over HTTP without authentication and can lead to full takeover of the affected ADF component. The CVSS 3.1 base score is 9.8, and CISA added it to the Known Exploited Vulnerabilities catalog.

Impact

An unauthenticated attacker can achieve full compromise of the ADF component, with high confidentiality, integrity and availability impact, effectively taking over the affected application.

Attack surface

Reached over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed ADF Faces deployment on the affected versions is in scope.

Exploitation

Listed in CISA KEV since 2024-09-18 with a 2024-10-09 remediation due date, indicating known exploitation in the wild. EPSS 30-day probability is 0.62478 (99.1st percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Oracle April 2022 Critical Patch Update (cpuapr2022) for ADF 12.2.1.3.0 and 12.2.1.4.0, or follow the Fusion Middleware Patch Advisor guidance.
  • If patching is not immediately possible, restrict network access to ADF Faces endpoints and discontinue use if no mitigation is available, per CISA required action.
  • Place ADF deployments behind authentication-aware reverse proxies or WAF rules that block untrusted serialized payloads where feasible.
  • Inventory all ADF Faces instances, including those bundled via Oracle JDeveloper, to confirm which hosts run the affected versions.
  • Monitor for and remove unnecessary external exposure of ADF Faces HTTP endpoints.

Detection

  • Inspect HTTP request bodies to ADF Faces endpoints for serialized Java object streams (for example base64 or binary markers such as rO0AB or AC ED 00 05).
  • Alert on anomalous POST traffic to ADF Faces URLs from unauthenticated or unfamiliar source IPs.
  • Review application and web server logs for deserialization errors, class-loading anomalies or unexpected process spawning on ADF hosts.
  • Correlate ADF host activity with outbound connections or new child processes that may indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-21445 to the Known Exploited Vulnerabilities catalog on 18 September 2024 as "Oracle ADF Faces Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 October 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-21445 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-35243Oracle application development framework improper access control vulnerabilityVulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions th…EPSS 0.16%7.2CVE-2026-46769Oracle application development framework improper access control vulnerabilityVulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Shared Components). Supported…EPSS 0.49%6.1CVE-2026-46770Oracle application development framework improper access control vulnerabilityVulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Security Framework). Supported ve…EPSS 0.25%4.7CVE-2026-46772Oracle application development framework improper access control vulnerabilityVulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions th…EPSS 0.14%4.1CVE-2026-46771Oracle application development framework improper access control vulnerabilityVulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java Business Objects). Supported…EPSS 0.14%2.4CVE-2019-2899Oracle application development framework vulnerabilityVulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: OAM). Supported versions that are affected are 11.1.1.…EPSS 0.88%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed

Source: NIST National Vulnerability Database (record CVE-2022-21445), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.