Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle Reports Developer 12.2.1.19.0 that allows a locally connected attacker to bypass authentication entirely, enabling creation, deletion, or modification of critical data. The weakness results in confidentiality and integrity impacts, and it may also give the attacker access to other internal components due to the change in scope. The CVSS 3.1 base score of 9.3 reflects these severe impacts.

Affected Systems

The affected product is Oracle Corporation’s Oracle Reports Developer, specifically version 12.2.1.19.0. The vulnerability may also affect other Oracle Fusion Middleware components that rely on the same security mechanisms.

Risk and Exploitability

The CVSS vector indicates an adjacent network attack (AV:A) with low complexity (AC:L) and no privileged user or user interaction required (PR:N, UI:N). The change in scope (S:C) means exploitation could affect access to or modification of additional internal components. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability. The high CVSS score and lack of authentication requirement classify it as a high‑risk vulnerability. The vulnerability is not listed in the CISA KEV catalog, yet the potential for internal compromise should not be underestimated.

Generated by OpenCVE AI on August 27, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or update release for Oracle Reports Developer 12.2.1.19.0 announced in the Oracle security alert referenced above.
  • Restrict physical network access to the server hosting Reports Developer by placing it on a separate VLAN or network segment and enforcing strict device authentication policies.
  • Configure Reports Developer to require strong credentials, disable local access to critical functions where possible, enforce TLS for all internal communications, and review audit logs for unauthorized access attempts.

Generated by OpenCVE AI on August 27, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Physical Access Exploit in Oracle Reports Developer Enables Unauthorized Data Manipulation

Thu, 27 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Local Network Access Vulnerability Compromises Oracle Reports Developer
Weaknesses CWE-287

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Local Network Access Vulnerability Compromises Oracle Reports Developer
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Reports Developer accessible data as well as unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:24:26.498Z

Reserved: 2026-07-14T14:54:48.744Z

Link: CVE-2026-62613

cve-icon Vulnrichment

Updated: 2026-08-26T13:49:08.758Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:13.900

Modified: 2026-08-26T17:16:25.410

Link: CVE-2026-62613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:00:14Z

Weaknesses