Impact
This flaw allows an attacker without authentication to send HTTP requests that create, delete, modify, or read data within Oracle Reports Developer. The exposed endpoints lack proper access controls, enabling the attacker to tamper with critical information or expose it to unauthorized viewers, thereby damaging both confidentiality and integrity of all data accessed through the application.
Affected Systems
Oracle Reports Developer (Oracle Fusion Middleware) version 12.2.1.19.0 is affected, as identified in the CNA documentation. No other versions or variants are listed.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 reflects severe confidentiality and integrity impact. The vulnerability is exploitable remotely over HTTP without authentication, making it trivial for an adversary with network reach. A EPSS score of 0.303% indicates a low probability of exploitation in the wild, but the absence of authentication and direct network exposure still give attackers an easy attack path. The issue is not listed in the CISA KEV catalog, yet its severity dictates immediate action.
OpenCVE Enrichment