Impact
The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content, requiring human interaction from a user other than the attacker. Successful exploitation can lead to a full takeover of the product, affecting the confidentiality, integrity, and availability of the system.
Affected Systems
Affected is Oracle WebCenter Content, version 14.1.2.0.0. No other vendors or products are listed as impacted in the provided data.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. The EPSS score is below 1 %, suggesting a low probability of exploit at the time of the assessment, and the vulnerability is not listed in the CISA KEV catalog. However, the requirement of network access via HTTP combined with the need for human interaction makes the attack vector primarily network-based and user‑dependent. The scope change described may allow related Oracle Fusion Middleware components to be affected if compromised.
OpenCVE Enrichment