Impact
The flaw resides in the Security and Authentication module of the Oracle Fusion Middleware component. Once exploited, the attacker can fully take over the Reports Developer service, with high confidentiality, integrity, and availability impact—this corresponds to an unspecified access control weakness.
Affected Systems
The affected product is Oracle Reports Developer 12.2.1.19.0, part of Oracle Fusion Middleware. No other product versions are listed in the CNA data as affected, and the impact is confined to this specific release.
Risk and Exploitability
The CVSS score of 8.8 signals high severity while the EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based exploitation of the HTTP interface, whereby an attacker sends a specially crafted request and relies on a user to interact with a malicious link or form to complete the compromise. Based on the description, it is inferred that the human interaction requirement involves action from a user other than the attacker, such as clicking a link that triggers the authentication bypass. Despite the low EPSS, the potential for a full takeover makes this a high-impact risk, especially for systems exposed to the internet or internal networks.
OpenCVE Enrichment