Impact
This vulnerability allows an attacker who can reach the WebCenter Content server over HTTP to cause unauthorized creation, deletion or modification of critical content without proper authentication. Because the vulnerability is exploitable from the network and does not require special privileges on the server, the attacker can affect any data accessible through the application. The CVE description notes that human interaction from a person other than the attacker is needed, suggesting that the attack may rely on social engineering or a user following a malicious link. The flaw resides in improper access control and authentication handling in the Content Server component, enabling the attacker to exert full control over the application’s data once the request is accepted.
Affected Systems
The affected product is Oracle WebCenter Content by Oracle Corporation, version 14.1.2.0.0. No other vendors or product versions are listed.
Risk and Exploitability
The CVSS 3.1 base score of 9.3 indicates high confidentiality and integrity impact. The EPSS score is below 1 %, suggesting a very low current exploitation probability, and the vulnerability is not present in the CISA KEV catalog. Because the flaw can be triggered over a normal HTTP connection, the likely attack vector is remote network access to the WebCenter Content server, possibly combined with social‑engineering techniques to obtain the necessary human interaction.
OpenCVE Enrichment