Impact
An unauthenticated flaw in Oracle Reports Developer permits an attacker with network access to the IIOP interface to execute arbitrary code, allowing full compromise of the application and severe impacts on confidentiality, integrity, and availability.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0, part of Oracle Fusion Middleware, is affected. The product is provided by Oracle Corporation.
Risk and Exploitability
The CVSS Base Score of 9.8 indicates a critical severity with high impacts on confidentiality, integrity, and availability. The EPSS score of < 1% reflects a very low probability of exploitation in the broader ecosystem. However, the vulnerability does not require authentication and is reachable via the network IIOP interface. If an attacker succeeds, they would gain full control over the Oracle Reports Developer instance. The vulnerability is not listed in CISA KEV, and no public exploit is currently documented.
OpenCVE Enrichment