Impact
A flaw in the Security and Authentication component of Oracle Reports Developer permits an attacker with physical or adjacent network access to bypass authentication and take complete control of the application. Because no credentials are required, the vulnerability can be exploited by anyone who can reach the host through the local communication segment. Once compromised, an attacker can read, modify, or delete reports and potentially affect the confidentiality, integrity and availability of the data processed by the application. The CVSS vector (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates that all three core security properties are severely impacted when the flaw is exploited.
Affected Systems
Oracle Reports Developer version 14.1.2.0.0 is the only version listed as affected. The product is part of Oracle Fusion Middleware, and the vulnerability applies only to the Oracle Reports Developer component in that specific release.
Risk and Exploitability
The CVSS Base Score of 8.8 classifies this flaw as high severity. The EPSS score of less than 1 % shows that it is currently considered unlikely to be exploited, and it does not appear in the CISA KEV catalog. However, the attack requires physical or adjacent network proximity to the server, meaning it is only relevant to environments where an attacker can gain local or near‑local access. In such scenarios, the elevated confidentiality, integrity, and availability impacts could lead to significant operational disruption.
OpenCVE Enrichment