Impact
This flaw in Oracle Reports Developer 12.2.1.19.0 enables an attacker with physical access to the host’s communication segment to compromise the application without authentication. The vulnerability is categorized under access control weaknesses, allowing full takeover of the application, which in turn can lead to disclosure, tampering and denial of service of Oracle Reports data. The CVSS vector (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a local or adjacent network attack that does not require credentials and can affect confidentiality, integrity and availability.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0 from Oracle Corporation is affected. No other vendors or products are listed; the issue is confined to this single product version.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because exploitation requires physical or local network access, the likelihood of widespread attacks is lower than a remote vulnerability, but targeted or insider attacks can be highly damaging. The described exploit path allows unrestricted control of the application, making it critical for organizations with direct physical or local network connectivity to the Oracle Reports Developer server.
OpenCVE Enrichment