Impact
The flaw in Oracle WebCenter Content version 14.1.2.0.0 permits an unauthenticated attacker with network access over HTTP to compromise the product. It allows unauthorized creation, deletion, or modification of data and can grant full access to all data stored in WebCenter Content, resulting in confidentiality and integrity vulnerabilities. The issue arises from improper access control, as reflected by the CVSS 3.1 base score of 9.3.
Affected Systems
Affected software is Oracle WebCenter Content (Oracle Fusion Middleware) version 14.1.2.0.0. The vulnerability may additionally impact other Oracle products that integrate with WebCenter Content due to a scope change, but the primary impact is on WebCenter Content itself.
Risk and Exploitability
Although the CVSS score indicates very high severity, the EPSS score is below 1%, implying a low current exploitation probability. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is over the network via HTTP; the flaw is exploitable by an unauthenticated attacker but still requires human interaction from a user other than the attacker, which may mitigate the risk. The scope change indicates that a successful compromise could affect downstream applications that rely on WebCenter Content.
OpenCVE Enrichment