Impact
The vulnerability is an easy‑to‑exploit flaw in Oracle WebCenter Content’s Content Server component that allows an attacker with network access via HTTP to gain high‑privilege access and take complete control of the server. Successful exploitation yields full confidentiality, integrity, and availability compromise, enabling the attacker to read, modify, or delete data, install persistent backdoors, and potentially pivot to other applications through the scope‑changing nature of the flaw.
Affected Systems
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. The flaw can also impact other products that operate in concert with WebCenter Content due to the scope change.
Risk and Exploitability
The CVSS 3.1 Base Score of 9.1 indicates critical severity, with low exploitation probability per an EPSS score of < 1% and no listing in CISA KEV. The likely attack vector is over the network via HTTP, requiring a high‑privilege attacker. Successful attacks can lead to a full takeover of the Content Server and potentially further compromise connected systems.
OpenCVE Enrichment