Impact
A critical flaw exists in Oracle Reports Developer where remote unauthenticated access over IIOP can be used to compromise the application. The vulnerability is rated as CVSS 3.1 base 9.8 with complete confidentiality, integrity, and availability impact. Attackers with network reach to the IIOP port can exploit the weakness to take full control of the Oracle Reports Developer instance, effectively achieving a remote code execution scenario.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0 (part of Oracle Fusion Middleware) is affected. The product is offered by Oracle Corporation.
Risk and Exploitability
The CVSS score signals a critical severity, and while an EPSS score is not reported, the lack of KEV designation does not mitigate the high risk of exploitation. The vulnerability can be triggered from any externally reachable system that can reach the IIOP port, making it likely to be exploited in practice. Successful exploitation leads to complete takeover of the service, both from a confidentiality and availability standpoint.
OpenCVE Enrichment