Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the Security and Authentication component of Oracle Reports Developer. A low‑privileged attacker with network access via HTTP can exploit the flaw, leading to a takeover of the Reports Developer instance. The flaw is classified as a high‑severity remote access flaw with a CVSS 3.1 base score of 8.5, giving confidentiality, integrity, and availability damage. The base vector indicates a network attack, high attack complexity, low privilege, no user interaction, and a scope change that can affect other components.

Affected Systems

Oracle Reports Developer version 12.2.1.19.0 is affected, as indicated by the CNA and the supported version information. No other versions or products are listed as impacted.

Risk and Exploitability

The EPSS score is not available, but the high CVSS score highlights a serious risk. Because the vulnerability is reachable over HTTP, an attacker on the same network can exploit it without authentication. The flaw is not listed in the CISA KEV catalog, so no known active exploits have been reported yet, yet the combination of remote access and scope change implies the potential for widespread impact.

Generated by OpenCVE AI on August 19, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for Oracle Reports Developer 12.2.1.19.0.
  • Restrict inbound HTTP access to the Reports Developer service, allowing only trusted IP ranges or VPN connections.
  • Implement strong authentication or remove unused HTTP endpoints to limit the attack surface.
  • Monitor traffic and logs for unusual HTTP requests that may indicate exploitation attempts.

Generated by OpenCVE AI on August 19, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Remote Access Exploit in Oracle Reports Developer Allowing Low‑Privileged Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:46.239Z

Reserved: 2026-07-14T14:54:48.745Z

Link: CVE-2026-62615

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:14.137

Modified: 2026-08-18T21:17:14.137

Link: CVE-2026-62615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T02:00:05Z

Weaknesses