Impact
Oracle Reports Developer version 14.1.2.0.0 contains a flaw in its security and authentication component that permits an attacker with local physical access to the server’s communication segment to compromise the application without authentication. The vulnerability allows a full takeover, impacting confidentiality, integrity, and availability.
Affected Systems
Only Oracle Reports Developer 14.1.2.0.0, part of Oracle Fusion Middleware, is affected. Because the flaw can alter the scope of impact, a successful compromise of Reports Developer may extend to other components that depend on it.
Risk and Exploitability
The CVSS base score of 9.6 signals a critical risk, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Attack requires physical proximity to the server’s local network, with no authentication or user interaction after accessing the local interface.
OpenCVE Enrichment