Oracle JDeveloper
product · product:oracle-jdeveloper
Coverage
1
first 2026-09-20 → last 2026-09-20
Latest activity
2026-09-29
Fifty credential-free, no-interaction flaws span Oracle's middleware, ERP, BI and telco-assurance lines, more…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, healthcare · regions: europe, switzerland
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about Oracle JDeveloper, newest first. Check the date before acting on an older one.
- Check every Oracle Fusion Middleware and Hyperion deployment against the affected component version strings (WebLogic Server 12.2.1.4.0 / 14.1.1.0.0 / 14.1.2.0.0; Access Manager and Internet Directory 12.2.1.4.0 / 14.1.2.1.0; Forms 12.2.1.19.0 / 14.1.2.0.0; Platform Security for Java 12.2.1.4.0 / 14.1.2.0.0; Hyperion Financial Management 11.2.26.0.000) and apply the September 2026 Critical Security Patch Update, which is an off-quarter release a January/April/July/October patch calendar does not schedule.2026-09-20CVE-2026-83021 +49
- Confirm that no Oracle Internet Directory LDAP listener, WebLogic web container or Access Manager authentication endpoint answers from outside its administrative network segment; all six flaws need no credential and no user interaction, so reachability is the whole of the exposure.2026-09-20CVE-2026-83021 +49
- Patch Oracle E-Business Suite 12.2.3-12.2.15 for CVE-2026-83327, CVE-2026-83452 and CVE-2026-83462 in this same release now: EBS is the product line Cl0p mass-exploited in 2025, and these three flaws need no credential and no user interaction.2026-09-20CVE-2026-83021 +49
Defender insights
What each entry about Oracle JDeveloper tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
CVEs
CVE-2026-17544CVE-2026-41635CVE-2026-44024CVE-2026-47065CVE-2026-70748CVE-2026-70756CVE-2026-70757CVE-2026-70913CVE-2026-71133CVE-2026-73940CVE-2026-73947CVE-2026-73950CVE-2026-73953CVE-2026-73956CVE-2026-73961CVE-2026-73963CVE-2026-82994CVE-2026-82995CVE-2026-83000CVE-2026-83020CVE-2026-83021CVE-2026-83035CVE-2026-83036CVE-2026-83037
Releases covered
Oracle JDeveloper
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-09-20/oracle-september-2026-cspu-five-unauthenticated-cvss-10 · ATT&CK page ↗
Entries about Oracle JDeveloper (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cl0p×1
- Oracle Access Manager×1
- Oracle Access Manager (Authentication Engine), unauthenticated flaw over HTTP, CVSS 10.0, September 2026 CSPU×1
- Oracle Access Manager Authentication Engine, unauthenticated CVSS 9.8 flaw, September 2026 CSPU×1
- Oracle Access Manager Authentication Engine, unauthenticated CVSS 9.8 flaw, September 2026 CSPU×1
- Oracle Access Manager Authentication Engine, unauthenticated CVSS 9.8 flaw, September 2026 CSPU×1
- Oracle Access Manager Third Party (Apache Mina), unauthenticated CVSS 9.8 flaw, September 2026 CSPU×1
- Oracle BI Publisher×1
Where this entity is cited
Source distribution
- advisories.ncsc.nl1 (50%)
- oracle.com1 (50%)