Impact
This vulnerability is located in Oracle Reports Developer’s Security and Authentication component. The flaw allows an unauthenticated attacker with network access over TCP to fully compromise the application, which would result in loss of confidentiality, integrity, and availability of the system and its data. The CVSS vector indicates no privileges are required and the impact is complete for all three dimensions.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0, part of Oracle Fusion Middleware, is affected. No other versions or products are listed.
Risk and Exploitability
A CVSS score of 9.8 indicates critical severity. The EPSS score of less than one percent indicates a low probability of exploitation, suggesting the flaw is not widely exploited but remains a significant risk if unpatched. The flaw is not listed in the CISA KEV catalog. The likely attack path is a remote TCP connection to the Reports Developer service, making the vulnerability widely reachable for attackers with network access. Because the flaw is easily exploitable, the risk of compromise remains high if the vulnerability persists unpatched.
OpenCVE Enrichment