Impact
An unauthenticated attacker who can reach Oracle Reports Developer over HTTP can read data that should be protected. The vulnerability allows full disclosure of all data exposed through the Reports Developer interface, resulting in a severe confidentiality breach. The weakness involves improper authentication and inadequate protection of sensitive information.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0 on Oracle Fusion Middleware is impacted. The vulnerability may also affect other integrated components because the scope is not limited to the Reports Developer itself.
Risk and Exploitability
The CVSS v3.1 base score of 8.6 signifies a high‑severity flaw. The EPSS score is less than 1%, indicating a very low but non‑zero exploitation probability. The vulnerability is not present in CISA's KEV catalog. Attackers do not need credentials; the vector is network‑based over HTTP, and the scope change points to possible collateral impact on other components.
OpenCVE Enrichment