Description
Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces) (versions 12.2.1.3.0 and 12.2.1.4.0 and prior) is vulnerable to a Java Object Deserialization remote code execution vulnerability. An attacker could exploit this vulnerability using specially-crafted serialized data to execute arbitrary code on the system or to perform a denial of service attack.
Remediation
Upgrade to the latest version of Oracle ADF Faces
References
Related Vulnerabilities
WordPress Plugin Gantry 4 Framework Remote Command Execution (4.1.3)
IBM WebSphere RCE Java Deserialization Vulnerability
TinyMCE ajax_create_folder remote code execution vulnerability
PHP 4.3.0 file disclosure and possible code execution
WordPress Plugin Duplicator-WordPress Migration Remote Code Execution (1.2.40)