Impact
An unauthenticated attacker who can reach Oracle Reports Developer over the network via SOAP can compromise the application. The flaw allows unauthorized reading of critical data, creates the possibility of inserting, updating, or deleting data, and can also induce a partial denial of service. The issue is classified as a high‑impact problem affecting confidentiality, integrity, and availability.
Affected Systems
The flaw affects Oracle Reports Developer version 12.2.1.19.0, a component of Oracle Fusion Middleware. Users running this specific build should assess whether the service is exposed to external networks and whether the SOAP interface is accessible.
Risk and Exploitability
The CVSS v3.1 score of 8.6 denotes high severity, with network access required but no authentication needed. Although EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, the ease of exploitation via a standard SOAP port implies a substantial threat to any environment that hosts the affected product without adequate protections.
OpenCVE Enrichment