Impact
This vulnerability exists in Oracle WebCenter Content 14.1.2.0.0 and allows an unauthenticated attacker who can reach the server over HTTP to compromise the system. The flaw is exploitable with low attack complexity, and it requires a user interaction that is not performed by the attacker. Once exploited, the attacker can take full control of the application, exposing confidential data, tampering with stored content, and disrupting its availability. The weakness is an improper access control that exposes the system to unauthorized takeover.
Affected Systems
Oracle WebCenter Content version 14.1.2.0.0.
Risk and Exploitability
The CVSS v3.1 Base Score of 9.6 indicates a critical impact to confidentiality, integrity, and availability. The EPSS score of less than 1% reflects a very low but nonzero probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is HTTP over the network, but successful exploitation requires additional human interaction that is not in the attacker's direct control, reducing the probability of automated attacks yet leaving the high impact if the conditions are met.
OpenCVE Enrichment