Impact
Oracle Reports Developer version 14.1.2.0.0 contains an easily exploitable vulnerability in the Security and Authentication component that allows an unauthenticated attacker to create, delete or modify data, read a subset of data, and cause the application to hang or crash. The flaw results in confidentiality, integrity, and availability impacts, with a CVSS 3.1 base score of 9.4.
Affected Systems
The affected product is Oracle Reports Developer 14.1.2.0.0 from Oracle Corporation. No other versions are listed as impacted.
Risk and Exploitability
The vulnerability can be triggered by network traffic sent over HTTP and does not require authentication or user interaction. With a CVSS score of 9.4 the severity is critical, the EPSS score is not available, and the issue is not yet listed in the CISA KEV catalog. Attackers can exploit it remotely and autonomously, making it highly likely to be leveraged if discovered.
OpenCVE Enrichment