Impact
The vulnerability exists in the Security and Authentication component of Oracle Reports Developer and allows an unauthenticated attacker with network access via TCP to compromise the service. The impact is a full takeover of Oracle Reports Developer, resulting in loss of confidentiality, integrity, and availability for the affected environment.
Affected Systems
Oracle Reports Developer version 14.1.2.0.0, part of Oracle Fusion Middleware, is affected. The product can be accessed over the network via TCP, exposing it to potential attackers without prior authentication.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates a high severity risk. The vulnerability requires no authentication and is reachable over the network via TCP. EPSS score is < 1% and it is not listed in CISA KEV.
OpenCVE Enrichment