Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Wed, 26 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Allows Full Application Takeover in Oracle Reports Developer |
Wed, 26 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo |
Tue, 25 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Authentication Bypass Enabling Full Application Compromise in Oracle Reports Developer | |
| Weaknesses | CWE-285 CWE-287 |
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Authentication Bypass Enabling Full Application Compromise in Oracle Reports Developer | |
| Weaknesses | CWE-285 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle reports Developer |
|
| CPEs | cpe:2.3:a:oracle:reports_developer:14.1.2.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle reports Developer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:00:52.797Z
Updated: 2026-08-26T03:56:22.580Z
Reserved: 2026-07-14T14:54:48.746Z
Link: CVE-2026-62635
Updated: 2026-08-25T16:21:08.210Z
Status : Analyzed
Published: 2026-08-18T21:17:17.387
Modified: 2026-08-26T17:27:55.717
Link: CVE-2026-62635
No data.