Impact
The Oracle Reports Developer component contains an unauthenticated remote access flaw that allows an attacker with network connectivity to connect over TCP and read all data the service exposes. The vulnerability grants full confidentiality of critical data and real or potential release of sensitive information. No integrity or availability impacts are described in the published details.
Affected Systems
Oracle Reports Developer 12.2.1.19.0 in Oracle Fusion Middleware is listed as the only affected version. No other releases or patches are mentioned as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.6 indicates high severity, but the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Although the attack vector allows an unauthenticated attacker to connect over TCP and potentially impact additional products through a scope change, the low EPSS indicates that exploitation is unlikely. If exploited, the attacker could gain complete access to all data the service exposes.
OpenCVE Enrichment