RULE(RULE ID:324283)

Rule General Information
Release Date: 2020-02-03
Rule Name: Oracle JDeveloper ADF Faces Untrusted Deserialization Vulnerability (CVE-2019-2904)
Severity:
CVE ID:
Rule Protection Details
Description: Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Others
Reference: http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://www.oracle.com/security-alerts/cpujan2020.html
ZeroDayInitiative:ZDI-19-1024
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html