Impact
A flaw in the Client Bundle component of Oracle WebCenter Enterprise Capture allows a low‑privileged attacker with network access to execute arbitrary code. The vulnerability can be exploited over the T3 or IIOP interfaces and results in complete compromise of confidentiality, integrity, and availability of the application. The affected code path grants the attacker privileges that are higher than those originally available, enabling a full takeover of the WebCenter instance.
Affected Systems
The vulnerability affects Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0. According to the advisories, exploitation may also extend beyond the Client Bundle and impact other modules within Oracle Fusion Middleware, although specific downstream products are not enumerated.
Risk and Exploitability
The CVSS score of 9.9 categorizes this flaw as critical, while the EPSS score of less than 1 % indicates the current probability of exploitation is low but not negligible. The vulnerability is not listed in CISA's KEV catalog. The attack vector is network‑based via the T3 and IIOP ports. Based on the description, the scope change suggests that compromising the Client Bundle could allow an adversary to affect additional components that depend on it.
OpenCVE Enrichment