Impact
Based on the description, it is inferred that an attacker who physically accesses the hardware communication segment of Oracle Reports Developer can create, delete, or modify data and read all data accessible to the application. This is an improper authorization (CWE‑284) bypass that allows unauthenticated local attackers to bypass security controls and alter or retrieve any data the application holds. The vulnerability, rated 9.3 on CVSS 3.1, imposes full confidentiality and integrity breach with no availability impact.
Affected Systems
Oracle Reports Developer for Oracle Fusion Middleware, specifically version 14.1.2.0.0. The issue in this component may also affect other products that share or rely on the same security and authentication mechanisms due to a potential scope change.
Risk and Exploitability
The high CVSS score reflects significant risk, and based on the description it is inferred that the likely attack vector is local or near‑local physical access to the communication segment, as indicated by the adjacent network vector (AV:A), requiring local or near‑local physical presence and is otherwise easily exploitable. The EPSS score is less than 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, yet its severity warrants urgent attention. An attacker can leverage the flaw to gain unauthorized creation, deletion, modification, or reading of data, impacting confidentiality and integrity across the affected system and potentially other products that share the authentication boundary.
OpenCVE Enrichment