Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Wed, 26 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated UDP Exploit Compromises Oracle Reports Developer |
Tue, 25 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Network Exploit Enables Complete Compromise of Oracle Reports Developer | |
| Weaknesses | CWE-269 |
Tue, 25 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Fri, 21 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Network Exploit Enables Complete Compromise of Oracle Reports Developer | |
| Weaknesses | CWE-269 |
Fri, 21 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated UDP Vulnerability Enabling Takeover of Oracle Reports Developer | |
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated UDP Vulnerability Enabling Takeover of Oracle Reports Developer | |
| Weaknesses | CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle reports Developer |
|
| CPEs | cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle reports Developer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:00:46.993Z
Updated: 2026-08-25T15:16:12.751Z
Reserved: 2026-07-14T14:54:48.745Z
Link: CVE-2026-62617
Updated: 2026-08-25T14:37:37.475Z
Status : Analyzed
Published: 2026-08-18T21:17:14.370
Modified: 2026-08-26T17:17:08.250
Link: CVE-2026-62617
No data.