Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw permits an unauthenticated attacker who can reach the Oracle Reports Developer instance over HTTP to read or otherwise obtain data that should be protected. The vulnerability is described as easily exploitable, resulting in a high confidentiality impact that can give an attacker complete visibility into all data accessible through the Reports Developer interface. No direct denial‑of‑service or code execution is claimed, but the loss of sensitive information is a severe outcome for organizations using this product.

Affected Systems

Oracle Reports Developer version 12.2.1.19.0, released as part of Oracle Fusion Middleware, is vulnerable. No other product variants are listed as affected, but the scope change noted indicates that attacks could also affect additional integrated components.

Risk and Exploitability

The CVSS v3.1 base score of 8.6 indicates a high‑severity flaw. The EPSS score is not available, yet the descriptive language suggests an easily exploitable condition. The vulnerability is not listed in CISA’s KEV catalog, but the attack vector is network based, using HTTP, and an attacker does not need any specialized credentials or privileged access. Because the scope of the impact is collateral, the overall risk to an organization is significant, especially when the service is exposed to untrusted networks.

Generated by OpenCVE AI on August 19, 2026 at 01:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Reports Developer to a version that resolves this flaw, as announced by Oracle in their latest security advisory.
  • If an upgrade is not immediately possible, restrict HTTP access to the Reports Developer instance by tightening firewall rules so that only trusted internal IP ranges can connect.
  • Implement monitoring of abnormal request patterns to detect potential exploitation attempts and isolate the affected service if suspicious activity is detected.

Generated by OpenCVE AI on August 19, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Vulnerability in Oracle Reports Developer 12.2.1.19.0 Leading to Unauthorized Data Access
Weaknesses CWE-200
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:47.935Z

Reserved: 2026-07-14T14:54:48.745Z

Link: CVE-2026-62620

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:15.690

Modified: 2026-08-18T21:17:15.690

Link: CVE-2026-62620

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T01:45:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-287

    Improper Authentication