Impact
A flaw in Oracle Reports Developer 12.2.1.19.0 enables an unauthenticated attacker who can reach the system over the network via SMTP to perform unauthorized updates, inserts, or deletions of data. The same exploit can trigger a partial denial of service by exhausting resources or disrupting normal operation of the application. The impact is limited to integrity and availability, with no direct confidentiality impact reported.
Affected Systems
Oracle Reports Developer, version 12.2.1.19.0 is the only version identified as affected. The vulnerability may also have scope implications that could affect associated Oracle Fusion Middleware products, although no specific additional products are listed.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑to‑medium severity, with low attack complexity and no authentication required. Because the attacker only needs network access over SMTP, the threat is considered readily exploitable. EPSS data is not available, and the flaw is not listed in CISA KEV, but the lack of mitigation could still lead to significant operational disruption if an attacker succeeds.
OpenCVE Enrichment