Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-08-18
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who can reach Oracle Reports Developer over the network via SOAP can compromise the application. The flaw allows unauthorized reading of critical data, creates the possibility of inserting, updating, or deleting data, and can also induce a partial denial of service. The issue is classified as a high‑impact problem affecting confidentiality, integrity, and availability.

Affected Systems

The flaw affects Oracle Reports Developer version 12.2.1.19.0, a component of Oracle Fusion Middleware. Users running this specific build should assess whether the service is exposed to external networks and whether the SOAP interface is accessible.

Risk and Exploitability

The CVSS v3.1 score of 8.6 denotes high severity, with network access required but no authentication needed. Although EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, the ease of exploitation via a standard SOAP port implies a substantial threat to any environment that hosts the affected product without adequate protections.

Generated by OpenCVE AI on August 19, 2026 at 01:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Reports Developer 12.2.1.19.0 or later
  • Restrict network exposure of the SOAP endpoint using firewall or VPN rules to limit access to trusted hosts
  • Configure or enforce strict authentication mechanisms for the Reports Developer service to prevent unauthenticated usage
  • Monitor system logs for abnormal SOAP activity and suspicious data modifications

Generated by OpenCVE AI on August 19, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP Remote Access and Partial DoS in Oracle Reports Developer
Weaknesses CWE-284
CWE-693

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:49.549Z

Reserved: 2026-07-14T14:54:48.745Z

Link: CVE-2026-62625

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:16.253

Modified: 2026-08-18T21:17:16.253

Link: CVE-2026-62625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T01:45:16Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-693

    Protection Mechanism Failure