Impact
A vulnerability in Oracle Reports Developer allows an unauthenticated attacker with network access via HTTP to take over the application, compromising confidentiality, integrity, and availability. The flaw resides in the Security and Authentication component. Based on the description, the vulnerability is inferred to involve improper access control (CWE‑284) and improper authentication (CWE‑287), enabling remote exploitation without any privileged credentials or user interaction.
Affected Systems
Oracle Reports Developer version 12.2.1.19.0 is affected; all deployments of this specific version of Oracle Fusion Middleware are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of <1% indicates a very low, but non‑zero probability of exploitation. The advisory notes that the vulnerability is easily exploitable, and it is not listed in the CISA KEV catalog. Its high impact and lack of authentication requirements suggest a high threat level for attackers with HTTP access to the affected instance.
OpenCVE Enrichment