Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
Wed, 26 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Network Exploit Enables Full Compromise of Oracle Reports Developer via IIOP |
Tue, 25 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unauthenticated IIOP Access in Oracle Reports Developer | |
| Weaknesses | CWE-287 |
Tue, 25 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Fri, 21 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unauthenticated IIOP Access in Oracle Reports Developer | |
| Weaknesses | CWE-287 |
Wed, 19 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle Reports Developer Unauthenticated IIOP Remote Code Execution Vulnerability | |
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle Reports Developer Unauthenticated IIOP Remote Code Execution Vulnerability | |
| Weaknesses | CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle reports Developer |
|
| CPEs | cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle reports Developer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-08-25T15:15:00.293Z
Reserved: 2026-07-14T14:54:48.745Z
Link: CVE-2026-62624
Updated: 2026-08-25T14:37:44.423Z
Status : Analyzed
Published: 2026-08-18T21:17:16.143
Modified: 2026-08-26T17:17:49.460
Link: CVE-2026-62624
No data.
OpenCVE Enrichment
Updated: 2026-08-26T04:45:05Z