{"cve":"CVE-2026-62617","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"12.2.1.19.0"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Reports Developer","source":"cna","vendor":"Oracle Corporation"},"product":"reports_developer","vendor":"oracle"}],"created":"2026-08-19T02:00:05.013017+00:00","title":"Unauthenticated UDP Exploit Compromises Oracle Reports Developer","updated":"2026-08-26T04:15:04.266764+00:00","vendors":["oracle","oracle$PRODUCT$reports_developer"]},"epss":{"score":0.00508},"mitre":{"cpes":["cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*"],"created":"2026-08-18T21:00:46.993000+00:00","description":"Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication).   The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer.  Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/62xxx/CVE-2026-62617.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-25T15:16:12.751000+00:00","vendors":["oracle","oracle$PRODUCT$reports_developer"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*"],"created":"2026-08-18T21:17:14.370000+00:00","description":"Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication).   The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer.  Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-62617.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-26T17:17:08.250000+00:00","vendors":["oracle","oracle$PRODUCT$reports_developer"],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-08-18T21:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication).   The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer.  Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$reports_developer"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$reports_developer"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"4312a250-4022-4899-ab13-a192212aeef2"},{"created":"2026-08-19T02:15:00+00:00","data":[{"details":{"new":"Unauthenticated UDP Vulnerability Enabling Takeover of Oracle Reports Developer","old":null},"type":"title"},{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"15377ce9-f0df-4de9-8430-2bbd4ece3f3f"},{"created":"2026-08-21T09:00:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated UDP Vulnerability Enabling Takeover of Oracle Reports Developer"},"type":"title"},{"details":{"added":[],"removed":["CWE-284"]},"type":"weaknesses"}],"id":"46fc0614-b25b-40ed-808c-03b2c9c76b85"},{"created":"2026-08-21T11:45:00+00:00","data":[{"details":{"new":"Unauthenticated Network Exploit Enables Complete Compromise of Oracle Reports Developer","old":null},"type":"title"},{"details":{"added":["CWE-269"],"removed":[]},"type":"weaknesses"}],"id":"6b154a65-da3b-4a93-88c1-df25440539fb"},{"created":"2026-08-25T16:30:00+00:00","data":[{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"},{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"a2faeab4-313e-4a82-977b-14e8cbfdbf47"},{"created":"2026-08-25T19:00:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated Network Exploit Enables Complete Compromise of Oracle Reports Developer"},"type":"title"},{"details":{"added":[],"removed":["CWE-269"]},"type":"weaknesses"}],"id":"db2815e7-3c60-422a-bcde-96266def8a3d"},{"created":"2026-08-26T04:30:00+00:00","data":[{"details":{"new":"Unauthenticated UDP Exploit Compromises Oracle Reports Developer","old":null},"type":"title"}],"id":"23c70983-384d-47d7-a000-440dcdce8ed1"}],"cpes":{"data":["cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-18T21:00:46.993000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication).   The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer.  Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00508},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Unauthenticated UDP Exploit Compromises Oracle Reports Developer","provider":"enrichment"},"updated":{"data":"2026-08-26T04:15:04.266764+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$reports_developer"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-284"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-08-18T21:00:46.993000+00:00","description":"Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication).   The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Reports Developer.  Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-08-25T14:37:37.475000+00:00","vendors":[],"vulnrichment_repo_path":"2026/62xxx/CVE-2026-62617.json","weaknesses":["CWE-284"]}}