Impact
A flaw in Oracle Reports Developer 14.1.2.0.0 allows an attacker who can reach the system over HTTP to gain complete control of the application without needing credentials. This results in the loss of confidentiality, integrity, and availability for all data managed by the Reports Developer environment. The weakness is a form of authentication bypass that permits unrestricted access.
Affected Systems
Oracle Reports Developer 14.1.2.0.0 delivered as part of Oracle Fusion Middleware. No other product or version is listed as affected.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation. The lack of a requirement for privileged access and the requirement only of public network connectivity make exploitation highly feasible. The vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog, but its characteristics suggest that attackers could prepare a publicly available exploit quickly.
OpenCVE Enrichment