Impact
Oracle Reports Developer contains a flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The vulnerability enables full takeover of the service, potentially allowing an attacker to run arbitrary code or gain complete control, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Oracle Reports Developer version 14.1.2.0.0, part of Oracle Fusion Middleware. This is the only supported release identified as impacted, and the weakness resides in the Security and Authentication component.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 signifies very high severity. The EPSS score of < 1% indicates that, while exploitation probability is low, the lack of authentication and the simple HTTP request required make the vulnerability a realistic threat for systems exposed to untrusted traffic. The vulnerability is not cataloged in CISA’s KEV, but its high score warrants urgent attention.
OpenCVE Enrichment