Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the Security and Authentication component of Oracle Reports Developer. A low‑privileged attacker with network access via HTTP can exploit the flaw, leading to a takeover of the Reports Developer instance. The flaw is classified as a high‑severity remote access flaw with a CVSS 3.1 base score of 8.5, giving confidentiality, integrity, and availability damage. The base vector indicates a network attack, high attack complexity, low privilege, no user interaction, and a scope change that can affect other components.

Affected Systems

Oracle Reports Developer version 12.2.1.19.0 is affected, as indicated by the CNA and the supported version information. No other versions or products are listed as impacted.

Risk and Exploitability

The EPSS score is 0.27%, indicating a very low exploitation probability, but the high CVSS score highlights a serious risk. Because the vulnerability is reachable over HTTP, an attacker on the same network can exploit it without authentication. The flaw is not listed in the CISA KEV catalog, so no known active exploits have been reported yet; yet the combination of remote access and scope change implies the potential for widespread impact.

Generated by OpenCVE AI on August 21, 2026 at 11:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for Oracle Reports Developer 12.2.1.19.0.
  • Restrict inbound HTTP access to the Reports Developer service, allowing only trusted IP ranges or VPN connections.
  • Implement strong authentication or remove unused HTTP endpoints to limit the attack surface.
  • Monitor traffic and logs for unusual HTTP requests that may indicate exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Access Vulnerability Allowing Full Takeover of Oracle Reports Developer
Weaknesses CWE-284

Fri, 21 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Remote Access Exploit in Oracle Reports Developer Allowing Low‑Privileged Takeover
Weaknesses CWE-284

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Remote Access Exploit in Oracle Reports Developer Allowing Low‑Privileged Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:16:21.289Z

Reserved: 2026-07-14T14:54:48.745Z

Link: CVE-2026-62615

cve-icon Vulnrichment

Updated: 2026-08-25T14:25:13.209Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:14.137

Modified: 2026-08-26T17:16:42.020

Link: CVE-2026-62615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:30:04Z

Weaknesses