Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability enables an unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. The flaw provides full unauthorized read access and allows the attacker to update, insert, or delete data that should be protected. The CVSS 3.1 base score of 9.3 reflects high confidentiality impact and moderate integrity impact, indicating a severe potential for data exposure and manipulation.

Affected Systems

OEM customers using Oracle Reports Developer version 12.2.1.19.0, part of Oracle Fusion Middleware’s Security and Authentication component. The vulnerability’s scope change means that exploitation could also affect additional products within the same environment.

Risk and Exploitability

The CVSS vector captures a network attack with low complexity, no privileges, and no user interaction, confirming that the vulnerability is easily exploitable from outside the organization. An EPSS score of 0.26% indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog, but the high CVSS score alone warrants urgent attention. A direct HTTP request to the vulnerable service can trigger the unauthorized data access and tampering, making this risk immediate and significant.

Generated by OpenCVE AI on August 27, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch for Reports Developer version 12.2.1.19.0 as soon as it becomes available.
  • Restrict HTTP access to the Reports Developer service using network firewalls or IAM policies so only trusted internal hosts can reach it.
  • Enforce authentication and proper role‑based access controls within Reports Developer to prevent unauthorized data manipulation.
  • Monitor web server logs for anomalous HTTP requests that might indicate exploitation attempts.

Generated by OpenCVE AI on August 27, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Access and Modification in Oracle Reports Developer via HTTP
Weaknesses CWE-306

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Access and Modification in Oracle Reports Developer via HTTP
Weaknesses CWE-284
CWE-306

Fri, 21 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle Reports Developer 12.2.1.19.0
Weaknesses CWE-284

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle Reports Developer 12.2.1.19.0
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:16:01.219Z

Reserved: 2026-07-14T14:54:48.745Z

Link: CVE-2026-62618

cve-icon Vulnrichment

Updated: 2026-08-25T14:33:34.528Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:14.560

Modified: 2026-08-26T17:17:13.260

Link: CVE-2026-62618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T00:30:14Z

Weaknesses