Impact
Oracle Reports Developer 12.2.1.19.0 contains a security flaw that can allow an attacker with low privileges and network access via HTTP to gain full control of the application. The vulnerability affects the security and authentication component, permitting the attacker to bypass normal authentication checks and achieve compromise. This results in complete loss of confidentiality, integrity, and availability for data handled by Reports Developer, potentially exposing sensitive reports and underlying database information.
Affected Systems
The affected product is Oracle Reports Developer, version 12.2.1.19.0, part of Oracle Fusion Middleware. No other versions or vendors are listed in the current advisories.
Risk and Exploitability
The CVSS v3.1 score of 8.8 indicates high severity, with network access and low attack complexity. Because the vulnerability can be exploited via HTTP from any external host without user interaction, the likelihood of successful exploitation is high for an attacker who can reach the target network. The EPSS score of < 1% indicates a very low, yet non‑zero probability of exploitation, while the vulnerability is not yet listed in the CISA KEV catalog. The documented exploit path suggests a practical attack scenario. The effective attack vector is inferred to be network‑based HTTP access to the Reports Developer web service, with low privilege attacker posture.
OpenCVE Enrichment