Impact
The flaw permits an unauthenticated attacker who can reach the Oracle Reports Developer instance over HTTP to read or otherwise obtain data that should be protected. The vulnerability is described as easily exploitable, resulting in a high confidentiality impact that can give an attacker complete visibility into all data accessible through the Reports Developer interface. No direct denial‑of‑service or code execution is claimed, but the loss of sensitive information is a severe outcome for organizations using this product.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0, released as part of Oracle Fusion Middleware, is vulnerable. No other product variants are listed as affected, but the scope change noted indicates that attacks could also affect additional integrated components.
Risk and Exploitability
The CVSS v3.1 base score of 8.6 indicates a high‑severity flaw. The EPSS score is not available, yet the descriptive language suggests an easily exploitable condition. The vulnerability is not listed in CISA’s KEV catalog, but the attack vector is network based, using HTTP, and an attacker does not need any specialized credentials or privileged access. Because the scope of the impact is collateral, the overall risk to an organization is significant, especially when the service is exposed to untrusted networks.
OpenCVE Enrichment