Impact
A flaw in the Oracle WebCenter Enterprise Capture client bundle enables an attacker with low privileges and network connectivity via the T3 protocol to compromise the application, resulting in full takeover. The vulnerability directly impacts confidentiality, integrity, and availability, as the attacker can execute arbitrary code and gain control of the targeted system.
Affected Systems
Oracle WebCenter Enterprise Capture version 12.2.1.4.0 and 14.1.2.0.0, issued by Oracle Corporation.
Risk and Exploitability
The CVSS v3.1 base score of 9.9 reflects a high severity, and the minimal EPSS score (<1%) indicates that exploitation is rare but possible. The vulnerability is not listed in the CISA KEV catalog, yet the attack vector is inseparable from the T3 network protocol, enabling a remote, low‑privilege attacker to reach the affected component.
OpenCVE Enrichment