Impact
Oracle Reports Developer version 14.1.2.0.0 contains a flaw in its security and authentication components that allows an unauthenticated attacker with network connectivity over HTTP to bypass authentication controls. The attacker can read sensitive data that the Reports Developer interface can expose and can also update, insert, or delete data, thereby violating confidentiality and compromising part of the integrity of the data set.
Affected Systems
Only Oracle Reports Developer 14.1.2.0.0 is explicitly listed as affected. The description notes that the vulnerability may also impact additional products, but no specific additional products are identified.
Risk and Exploitability
The CVSS 3.1 base score of 9.3 indicates critical severity with high confidentiality impact and lower integrity impact. The EPSS score is below 1%, implying the likelihood of exploitation is very low. The vulnerability is not included in the CISA KEV catalog. The attack is network‑based over HTTP, requires no authentication or user interaction, and presents a low exploitation barrier but a high potential for data compromise if the product is exposed.
OpenCVE Enrichment