Impact
Oracle Reports Developer version 14.1.2.0.0 is vulnerable to an unauthenticated network attack that can be triggered via HTTP. A successful exploitation results in complete takeover of the Report Developer process, compromising confidentiality, integrity, and availability. The weakness is an improper access control flaw within the Security and Authentication component of Oracle Fusion Middleware.
Affected Systems
The affected product is Oracle Reports Developer 14.1.2.0.0, a component of Oracle Fusion Middleware produced by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high severity vulnerability with confidentiality, integrity, and availability impact. Exploitation requires network access via HTTP, a high attack complexity, and no privileges or user interaction, making the vulnerability unauthenticated. The EPSS score of < 1% indicates a very low probability of exploitation, though it is not zero, and the issue is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request from an external network capable of reaching the Reports Developer service.
OpenCVE Enrichment