Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw in Oracle Reports Developer 12.2.1.19.0 enables an attacker with physical access to the host’s communication segment to compromise the application without authentication. The vulnerability is categorized under access control weaknesses, allowing full takeover of the application, which in turn can lead to disclosure, tampering and denial of service of Oracle Reports data. The CVSS vector (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a local or adjacent network attack that does not require credentials and can affect confidentiality, integrity and availability.

Affected Systems

Oracle Reports Developer version 12.2.1.19.0 from Oracle Corporation is affected. No other vendors or products are listed; the issue is confined to this single product version.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because exploitation requires physical or local network access, the likelihood of widespread attacks is lower than a remote vulnerability, but targeted or insider attacks can be highly damaging. The described exploit path allows unrestricted control of the application, making it critical for organizations with direct physical or local network connectivity to the Oracle Reports Developer server.

Generated by OpenCVE AI on August 19, 2026 at 11:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor supplied patch or upgrade to a newer, supported version of Oracle Reports Developer that includes the fix for this flaw.
  • Implement network segmentation to prevent unauthenticated users from accessing the physical communication segment that Oracle Reports Developer uses, ensuring that only authorized network zones can reach the application.
  • Limit physical access to the servers hosting Oracle Reports Developer, ensuring that only authorized personnel can physically interact with the system hardware.

Generated by OpenCVE AI on August 19, 2026 at 11:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Insider Access Enables Oracle Reports Developer Takeover
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:15:13.089Z

Reserved: 2026-07-14T14:54:48.745Z

Link: CVE-2026-62623

cve-icon Vulnrichment

Updated: 2026-08-25T14:25:18.693Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:16.030

Modified: 2026-08-26T17:17:43.243

Link: CVE-2026-62623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:30:02Z

Weaknesses