Impact
The vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture and allows a low‑privileged attacker with network access via HTTP to compromise the application. Successful exploitation results in a takeover of Oracle WebCenter Enterprise Capture, with full confidentiality, integrity, and availability impacts as reflected in the CVSS vector.
Affected Systems
Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected by this flaw.
Risk and Exploitability
The CVSS base score of 9.9 indicates a severe risk, and the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation at present. Although the vulnerability is not listed in the CISA KEV catalog, its scope change and the ability to achieve remote code execution mean that it is highly dangerous if discovered by adversaries.
OpenCVE Enrichment