Impact
A vulnerability in Oracle Reports Developer allows an unauthenticated attacker with network access via HTTP to take over the application, compromising confidentiality, integrity, and availability. The flaw resides in the Security and Authentication component, enabling remote exploitation without any privileged credentials or user interaction.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0 is affected. All deployments of this specific version of Oracle Fusion Middleware are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. Although EPSS data is unavailable, the advisory states the issue is easily exploitable. The vulnerability is not yet listed in the CISA KEV catalog, but its high impact and lack of authentication requirements suggest a high threat level for attackers with HTTP access to the affected instance.
OpenCVE Enrichment