Impact
A flaw in Oracle Reports Developer version 14.1.2.0.0 permits an attacker who can reach the service over HTTP to perform unauthorized creation, deletion or modification of data and to access all data stored in the application. This results in confidentiality and integrity impacts because the attacker can modify or exfiltrate information without logging in. The underlying weakness is a weakness in access control (CWE‑284).
Affected Systems
The vulnerability affects Oracle Reports Developer 14.1.2.0.0, a component of Oracle Fusion Middleware. No other versions are noted as vulnerable in the available data.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 indicates high severity, while the EPSS score is < 1% and the issue is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is network access via HTTP, with no user interaction required. An exploitable instance therefore poses a high risk of data tampering or unauthorized data exposure to any host exposing Oracle Reports Developer to the Internet.
OpenCVE Enrichment