Impact
This vulnerability in Oracle Reports Developer 12.2.1.19.0 enables an unauthenticated attacker with network access via IIOP to compromise the application. The flaw permits a takeover that results in full confidentiality, integrity, and availability loss, allowing attackers to bypass authentication and gain control over the system, leading to remote code execution.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0, part of Oracle Fusion Middleware. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 marks this as critical, with an attack vector that is network‑based and easy to exploit. The EPSS score of 0.00486 indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. An attacker could remotely gain full control over the target without needing credentials.
OpenCVE Enrichment