Impact
A flaw in Oracle Report Manager’s Reports Security component allows a low‑privileged attacker who can reach the service over HTTP to compromise the application. By exploiting this vulnerability the attacker can obtain unauthorized access to critical data or gain full access to any data exposed by Oracle Report Manager, and can also trigger a partial denial of service. The issue is considered easily exploitable according to Oracle’s assessment.
Affected Systems
Oracle Report Manager for Oracle E‑Business Suite, versions 12.2.3 through 12.2.15.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 7.1, with low exploitation effort (low privileges, network access over HTTP) and a very low EPSS likelihood of less than 1%. It is not currently catalogued in the CISA KEV list. The vector indicates that the attacker does not need user interaction and that the impact is primarily confidentiality and availability. Because the flaw can be triggered remotely by an unauthenticated attacker with network access, the risk to exposed systems remains significant, especially in environments where Oracle Report Manager is reachable from untrusted networks.
OpenCVE Enrichment