Description
Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated web service flaw that allows an attacker to use the SOAP interface of Oracle Reports Developer to read, modify, or delete data and to potentially cause a partial denial of service. Because the flaw exists in the security and authentication component of Oracle Fusion Middleware, a successful exploit impacts confidentiality, integrity, and availability of the data exposed through Reports Developer. The weakness permits unauthenticated usage, exposing the system to attackers without requiring valid credentials.

Affected Systems

Oracle Reports Developer version 12.2.1.19.0 is affected. The product is part of Oracle Fusion Middleware and is typically deployed on servers that expose a SOAP endpoint to client applications. Users deploying this build should verify whether the service resides on an internal network, whether the SOAP port is exposed externally, and if additional authentication or access controls are in place.

Risk and Exploitability

The CVSS v3.1 base score of 8.6 indicates high severity, and the vector shows that network access with no authentication is sufficient to exploit the vulnerability. EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ease of exploitation via a standard SOAP port creates a significant threat for any environment where the Reports Developer service is reachable from outside the trusted network. Attackers can immediately gain unauthorized read and write capabilities and may launch a partial denial of service to disrupt service availability.

Generated by OpenCVE AI on August 21, 2026 at 09:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Reports Developer 12.2.1.19.0 or newer
  • Restrict access to the SOAP endpoint with firewall or VPN rules to limit traffic to trusted hosts
  • Enforce authentication or other access controls for the Reports Developer service to prevent unauthenticated use
  • Monitor system logs for unusual SOAP activity or data modification attempts

Generated by OpenCVE AI on August 21, 2026 at 09:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Oracle Reports Developer Unauthenticated SOAP Access Vulnerability

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP Remote Access and Partial DoS in Oracle Reports Developer
Weaknesses CWE-284
CWE-693

Wed, 19 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated SOAP Remote Access and Partial DoS in Oracle Reports Developer
Weaknesses CWE-284
CWE-693

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle reports Developer
CPEs cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle reports Developer
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Reports Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:14.679Z

Reserved: 2026-07-14T14:54:48.745Z

Link: CVE-2026-62625

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:03.675Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:16.253

Modified: 2026-08-20T15:04:32.527

Link: CVE-2026-62625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses