Impact
Oracle WebCenter Portal suffers an unauthenticated exploit that allows any network user with HTTP access to compromise the entire portal. The flaw resides in the Security Framework component and is formally classified as an improper authorization weakness, enabling attackers to gain full control over the application, resulting in confidentiality, integrity, and availability loss. The likelihood of exploitation is high because the vulnerability requires no credentials and can be triggered over the network.
Affected Systems
The affected releases are Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0. These versions are included in the Oracle Fusion Middleware stack and are commonly deployed in enterprise portal environments.
Risk and Exploitability
The CVSS 3.1 base score of 10.0 marks this as critical. EPSS indicates a very low probability (<1%) of immediate exploitation, yet the combination of no authentication and a network access vector makes the risk significant. The vulnerability is not listed in the CISA KEV catalog, but its scope change and total takeover potential mean it should be treated with the highest priority. Attackers can reach the vulnerable HTTP endpoints from any external network, implying unrestricted attack surface.
OpenCVE Enrichment