Impact
A network‑based vulnerability exists in Oracle Reports Developer 14.1.2.0.0 that permits an unauthenticated attacker to create, delete, or modify data accessible through the application and to cause an application hang or crash. The flaw undermines the integrity of reports data and the availability of the service, allowing the attacker to disrupt normal business operations. The reported weakness results in a CVSS v3.1 score of 9.1.
Affected Systems
This issue affects Oracle Reports Developer 14.1.2.0.0, a component of Oracle Fusion Middleware’s Security and Authentication suite. The product is distributed by Oracle Corporation under the OEM name Oracle Reports Developer.
Risk and Exploitability
The CVSS score of 9.1 indicates severe impact on integrity and availability, and the vulnerability is described as easy to exploit. The EPSS score is less than 1% and the vulnerability is not yet listed in the CISA KEV catalog, indicating a low probability of exploitation given the low EPSS score, but the ease of exploit and lack of prerequisites still make it a real threat for organizations that expose Oracle Reports Developer to network traffic. Exploit conditions do not require any prior privileges or specialized knowledge, making the threat real for organizations that expose Oracle Reports Developer to network traffic.
OpenCVE Enrichment