Impact
The vulnerability is an unauthenticated web service flaw that allows an attacker to use the SOAP interface of Oracle Reports Developer to read, modify, or delete data and to potentially cause a partial denial of service. Because the flaw exists in the security and authentication component of Oracle Fusion Middleware, a successful exploit impacts confidentiality, integrity, and availability of the data exposed through Reports Developer. The weakness permits unauthenticated usage, exposing the system to attackers without requiring valid credentials.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0 is affected. The product is part of Oracle Fusion Middleware and is typically deployed on servers that expose a SOAP endpoint to client applications. Users deploying this build should verify whether the service resides on an internal network, whether the SOAP port is exposed externally, and if additional authentication or access controls are in place.
Risk and Exploitability
The CVSS v3.1 base score of 8.6 indicates high severity, and the vector shows that network access with no authentication is sufficient to exploit the vulnerability. EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ease of exploitation via a standard SOAP port creates a significant threat for any environment where the Reports Developer service is reachable from outside the trusted network. Attackers can immediately gain unauthorized read and write capabilities and may launch a partial denial of service to disrupt service availability.
OpenCVE Enrichment