Impact
Vulnerability allows an unauthenticated attacker with network access to SOAP endpoints to compromise Oracle Reports Developer. The flaw grants the attacker the ability to create, delete, or modify critical data and provides full read access to all data stored in the Reports Developer instance. The impact includes loss of data integrity and confidentiality, potentially exposing sensitive business information.
Affected Systems
Affected product is Oracle Reports Developer version 14.1.2.0.0, part of Oracle Fusion Middleware, available from Oracle Corporation. The product is targeted via SOAP interfaces and is commonly deployed in enterprise environments. No other versions are listed as impacted.
Risk and Exploitability
CVSS 3.1 Base Score 9.1 indicates high severity, with critical confidentiality and integrity impacts. EPSS score is not available, indicating no current public exploitation data. The vulnerability is not listed in CISA KEV catalog, suggesting no known actor exploitation yet. The lack of authentication allows easy remote exploitation from any network location that can reach the SOAP service, making it likely that a malicious actor could abuse this flaw without credentials.
OpenCVE Enrichment