Impact
Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware permits an unauthenticated attacker with network access via HTTP to compromise the application. The flaw is easily exploitable and grants full control over the Reports Developer instance, potentially leading to a full takeover. The CVSS v3.1 vector indicates that the attack can compromise confidentiality, integrity, and availability with a high impact (C:H/I:H/A:H).
Affected Systems
Oracle Corporation’s Oracle Reports Developer version 12.2.1.19.0, part of Oracle Fusion Middleware. Only this specific version is known to be affected.
Risk and Exploitability
With a CVSS base score of 9.8, the vulnerability is classified as critical, impacting confidentiality, integrity, and availability. The EPSS score is not available, but the absence of authentication requirements and the network‑based HTTP accessibility make exploitation straightforward. Although not listed in the CISA KEV catalog, the high severity and simple attack vector indicate a significant risk that attackers could exploit this flaw rapidly.
OpenCVE Enrichment