Impact
An unauthenticated attacker with network access can exploit a flaw in the Oracle Reports Developer component of Oracle Fusion Middleware (Security and Authentication). The vulnerability allows bypass of authentication controls, leading to full compromise of the application. This bypass aligns with CWE‑284 (Improper Access Control), enabling the attacker to execute arbitrary code and thereby compromise confidentiality, integrity, and availability.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0 on Oracle Fusion Middleware. No other versions are listed as affected in the data.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity, while the EPSS score is currently unavailable and the vulnerability is not listed in CISA KEV. Attackers require only network connectivity via UDP (AV:N), no user interaction or privilege, and can achieve a complete takeover of the Reports Developer service. The absence of an exploitation probability metric combined with a high severity rating highlights a substantial risk for organizations running this product.
OpenCVE Enrichment