Impact
Oracle Reports Developer 14.1.2.0.0 contains a vulnerability that allows an unauthenticated network attacker with access to the CORBA interface to take over the application. This flaw permits arbitrary code execution, compromising confidentiality, integrity, and availability. It is a classic instance of improper authentication leading to full remote code execution.
Affected Systems
The affected product is Oracle Reports Developer version 14.1.2.0.0, part of Oracle Fusion Middleware. Earlier revisions and later releases are not listed as impacted. Only deployment of this specific version is vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 rates it as critical. Exploitation requires no credentials and can be performed over the network by contacting the CORBA service, meaning an attacker can mount an attack from any external host. The EPSS score of < 1 % indicates a very low but non‑zero probability of exploitation; however, combined with the high CVSS score, the vulnerability remains a high‑risk issue. The issue is not yet catalogued in the CISA KEV list.
OpenCVE Enrichment