Impact
A flaw in the Oracle Reports Developer component of Oracle Fusion Middleware enables an unauthenticated attacker who can reach the system over the network using IIOP to take full control of the application. The vulnerability allows the attacker to bypass normal authentication checks and is classified as a high‑severity remote code execution flaw, providing complete confidentiality, integrity, and availability compromise. The flaw represents an access control weakness (CWE‑284).
Affected Systems
Oracle Reports Developer version 14.1.2.0.0 is affected. The system must be reachable over the network, with IIOP service enabled, for the flaw to be exploitable; no client‑side or privileged conditions are required.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 reflects the ease of exploitation, the lack of required privileges, and the impact on all CIA triad aspects. Although an EPSS score is very low (< 1%), the description indicates the vulnerability is easily exploitable. Because the flaw is not listed in the CISA KEV catalog, no current exploit is publicly confirmed, but the high severity justifies immediate attention. An unauthenticated attacker that can contact the IIOP port can trigger the flaw to gain full control.
OpenCVE Enrichment