Impact
The flaw in Oracle Reports Developer 12.2.1.19.0 permits an unauthenticated attacker who can reach the platform via IIOP to gain control of the application. Successful exploitation disrupts application availability and enables the attacker to take over the system.
Affected Systems
Oracle Corporation’s Reports Developer product running version 12.2.1.19.0 is affected; no other versions or variants are listed as vulnerable.
Risk and Exploitability
With a CVSS v3.1 base score of 9.8, this vulnerability is classified as critical and offers high confidentiality, integrity, and availability impact. EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog. The description indicates that exploitation is easily possible over the network without authentication, potentially allowing a complete takeover of the application when IIOP traffic is accessible.
OpenCVE Enrichment