Impact
Oracle Reports Developer in Oracle Fusion Middleware has a vulnerability that permits a low privileged attacker with network access over HTTP to compromise the application. Once exploited the attacker can create, delete or modify data accessible through Reports Developer, thereby breaching confidentiality and integrity of the system’s data assets.
Affected Systems
The product affected is Oracle Reports Developer, version 14.1.2.0.0 from Oracle Corporation. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high severity vulnerability. The EPSS score of < 1% shows that the theoretical probability of exploitation is very low but not zero, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is over the network via HTTP, requiring only low privilege, allowing a contended attacker to create, delete or modify accessible data without elevated permissions.
OpenCVE Enrichment