Impact
The Oracle Reports Developer product contains a vulnerability in its security and authentication component. Network attackers with low privileges can exploit it over HTTP to gain unauthorized read access to all data exposed by Reports Developer and, in some cases, update, insert or delete that data. The flaw can elevate an attacker’s influence beyond the initial entry point, impacting confidentiality strongly and integrity moderately. The associated CWE is improper authorization.
Affected Systems
Affected vendor is Oracle Corporation. The vulnerable product is Oracle Reports Developer, part of Oracle Fusion Middleware. The only published affected version is 12.2.1.19.0. No other product versions are listed. The product is accessed over HTTP and typically deployed on enterprise servers hosting business reports.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 reflects a high relative impact, and the vector indicates a network-based attack, high complexity and low privilege requirements, with an altered scope that can bring more system components under attack prior to final compromise. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, while the low adversarial effort suggests a realistically possible exploit. The vulnerability is not yet present in CISA’s KEV catalog. Attackers with simple network connectivity can potentially leverage the flaw to read or modify critical business data.
OpenCVE Enrichment