Impact
An Oracle Reports Developer 12.2.1.19.0 vulnerability in the Security and Authentication component lets a low‑privileged attacker who can reach the system through CORBA gain control of the application. The flaw is easily exploitable and enables an adversary to take over Oracle Reports Developer, leading to full compromise of the system’s confidentiality, integrity, and availability. This vulnerability is an instance of CWE-284, representing an improper access control flaw.
Affected Systems
The affected system is Oracle Reports Developer 12.2.1.19.0 distributed by Oracle Corporation. No other versions or products are listed as affected in the available data.
Risk and Exploitability
The CVSS score is 9.9, indicating critical severity. The EPSS score is < 1%, indicating a low probability of exploitation, but the presence of the flaw still warrants immediate action. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based (AV:N) with low attack complexity and low privileges required, meaning a remote attacker can trigger the flaw from any accessible network segment. Because the vulnerability can change scope, exploitation may also impact additional components within the Oracle Fusion Middleware stack.
OpenCVE Enrichment