Impact
The flaw resides in the Security Framework component of Oracle WebCenter Portal, enabling a low‑privileged attacker who can reach the portal over HTTP to fully compromise the application. A successful exploit compromises confidentiality, integrity, and availability of the portal, allowing the attacker to gain complete control over the system. The CVSS vector indicates ease of exploitation (AV:N, AC:L, PR:L) and a total compromise scope (S:C), underscoring the severity of the vulnerability.
Affected Systems
Oracle Corporation’s Oracle WebCenter Portal product, affected versions 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The CVSS base score of 9.9 reflects a catastrophic impact. The EPSS score of less than 1% suggests that, while the vulnerability is technically easy to exploit, it is currently uncommon in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need only network access to the portal via regular HTTP ports, and the low‑privilege requirement means that an authenticated user or an unauthenticated user with minimal permissions could mount the attack. The possibility of scope escalation indicates that impact could spread beyond the portal to related Oracle Fusion Middleware components.
OpenCVE Enrichment