Impact
A vulnerability in Oracle Reports Developer 14.1.2.0.0 allows an unauthenticated attacker who has access to the physical communication segment attached to the hardware where the product runs to compromise the application. The weakness is an improper access control flaw (CWE-284), which enables bypassing authentication and taking full control of the application. While the description does not explicitly state arbitrary code execution, the ability to takeover the application implies that an attacker can modify or execute commands within the application context.
Affected Systems
Oracle Reports Developer 14.1.2.0.0, part of Oracle Fusion Middleware, is affected. The vulnerability applies to installations of this specific version of the product and no other versions are mentioned.
Risk and Exploitability
The CVSS score of 8.8 indicates severe impact to confidentiality, integrity and availability. Exploitation requires physical proximity or access to the local network segment connected to the server, which limits the attack surface. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting that no known public exploits are presently available. Because the flaw entirely bypasses authentication for attackers with local access, the risk to any deployment that is not physically or network‑segmented remains high.
OpenCVE Enrichment