Impact
A flaw in Oracle Reports Developer allows attackers with only network access over HTTP to bypass authentication (CWE-284) and gain full control of the application, leading to a compromise that can affect confidentiality, integrity, and availability of the system. The CVSS score of 9.8 reflects the severe impact across all domains, and the vulnerability is easy to exploit.
Affected Systems
The affected product is Oracle Reports Developer, version 14.1.2.0.0, which is part of Oracle Fusion Middleware under the Security and Authentication component.
Risk and Exploitability
Because the flaw requires no credentials and can be triggered by unauthenticated HTTP traffic, attackers can easily mount an assault without any detectable entry barrier. The EPSS score of less than 1% indicates a low exploitation probability, yet the high CVSS base score and lack of mitigation in the public domain justify the elevated risk. The vulnerability is not listed in the CISA KEV catalog, however the combination of ease of exploitation and full application takeover warrants urgent attention. Attack vectors are limited to HTTP traffic targeting the exposed Reports Developer service.
OpenCVE Enrichment