Impact
The Oracle Reports Developer component of Oracle Fusion Middleware contains a weakness that allows an unauthenticated attacker with network access to the HTTP interface to compromise the application. By exploiting this flaw, an attacker can gain full control of Oracle Reports Developer, leading to loss of confidentiality, integrity, and availability of the application. The CVSS base score of 9.8 indicates catastrophic impact when successfully attacked.
Affected Systems
This weakness exists in Oracle Reports Developer version 14.1.2.0.0. The application is part of Oracle Fusion Middleware and is deployed on enterprise servers that expose the Reports Developer servlet to network traffic. Any installation of the affected version without applying an official fix is vulnerable.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the CVSS base score of 9.8, combined with a network attack vector (AV:N) and low attack complexity (AC:L), indicates a high impact if exploited. The absence of an authentication requirement (PR:N) and no user interaction (UI:N) mean the attack is uncomplicated, requiring only network connectivity to the exposed Reports Developer instance, but the low EPSS suggests a low likelihood of exploitation in the wild.
OpenCVE Enrichment