Impact
Oracle Reports Developer version 14.1.2.0.0 is vulnerable to an unauthenticated network attack that can be triggered via HTTP. A successful exploitation results in complete takeover of the Report Developer process, compromising confidentiality, integrity, and availability. The weakness falls under improper access control orchestrated through the Security and Authentication component of Oracle Fusion Middleware.
Affected Systems
The affected product is Oracle Reports Developer 14.1.2.0.0, a component of Oracle Fusion Middleware produced by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high severity vulnerability with confidentiality, integrity, and availability impact. Exploitation requires network access (HTTP) and high attack complexity but no privileges or user interaction, and it is unauthenticated. No EPSS score is publicly available, and the issue is not yet listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request from an external network capable of reaching the Reports Developer service.
OpenCVE Enrichment