Impact
A vulnerability exists in Oracle Reports Developer 12.2.1.19.0 that allows a locally connected attacker to bypass authentication entirely, enabling creation, deletion, or modification of critical data. The weakness results in confidentiality and integrity impacts, and it may also give the attacker access to other internal components due to the change in scope. The CVSS 3.1 base score of 9.3 reflects these severe impacts.
Affected Systems
The affected product is Oracle Corporation’s Oracle Reports Developer, specifically version 12.2.1.19.0. The vulnerability may also affect other Oracle Fusion Middleware components that rely on the same security mechanisms.
Risk and Exploitability
The CVSS vector indicates an adjacent network attack (AV:A) with low complexity (AC:L) and no privileged user or user interaction required (PR:N, UI:N). The change in scope (S:C) means exploitation could affect access to or modification of additional internal components. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability. The high CVSS score and lack of authentication requirement classify it as a high‑risk vulnerability. The vulnerability is not listed in the CISA KEV catalog, yet the potential for internal compromise should not be underestimated.
OpenCVE Enrichment