Impact
An unauthenticated attacker who can reach Oracle Reports Developer over TCP can exploit a flaw in the security and authentication component, bypassing normal login requirements. The vulnerability allows the attacker to execute arbitrary code on the target and ultimately take full control of the Reports Developer instance. The attack compromises confidentiality, integrity, and availability of the application and any data it exposes. The flaw is defined by CWE-284.
Affected Systems
Oracle Reports Developer 12.2.1.19.0 running as part of Oracle Fusion Middleware is affected. Users running this exact version of the product are at risk.
Risk and Exploitability
The CVSS v3.1 Base Score of 9.8 signals a critical risk scenario. Although the EPSS score is less than 1%, indicating a low overall exploitation probability across all systems, any exposed deployment remains an attractive target because the vulnerability is exploitable without initial credential or code injection. The flaw is not listed in the CISA KEV catalog, but the high CVSS score combined with the unauthenticated network access vector warrants urgent attention.
OpenCVE Enrichment