Impact
The vulnerability is in the Security and Authentication component of Oracle Reports Developer. A low‑privileged attacker with network access via HTTP can exploit the flaw, leading to a takeover of the Reports Developer instance. The flaw is classified as a high‑severity remote access flaw with a CVSS 3.1 base score of 8.5, giving confidentiality, integrity, and availability damage. The base vector indicates a network attack, high attack complexity, low privilege, no user interaction, and a scope change that can affect other components.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0 is affected, as indicated by the CNA and the supported version information. No other versions or products are listed as impacted.
Risk and Exploitability
The EPSS score is not available, but the high CVSS score highlights a serious risk. Because the vulnerability is reachable over HTTP, an attacker on the same network can exploit it without authentication. The flaw is not listed in the CISA KEV catalog, so no known active exploits have been reported yet, yet the combination of remote access and scope change implies the potential for widespread impact.
OpenCVE Enrichment