Impact
A vulnerability in Oracle WebCenter Content version 14.1.2.0.0 allows an attacker with low privileges and network access over HTTP to gain elevated privileges within the Content Server. The flaw permits unauthorized creation, deletion, or modification of critical data and, due to a scope change, could also affect additional applications in the Oracle Fusion Middleware stack. The identified weakness corresponds to CWE‑269, describing a privilege escalation scenario that compromises confidentiality and integrity of data stored in the system.
Affected Systems
Oracle Corporation’s WebCenter Content product, version 14.1.2.0.0, is affected. No other products or versions are listed in the vulnerability entry.
Risk and Exploitability
The CVSS 3.1 score of 8.7 indicates high severity. The EPSS score is below 1%, suggesting a low current probability of exploitation, and the issue is not listed in CISA’s KEV catalog. Exploitation requires network connectivity via HTTP, low‑privileged access, and active user interaction from an actor other than the attacker. The combination of high impact potential and low exploitation likelihood places the overall risk at moderate to high for environments that expose WebCenter Content to untrusted networks or users.
OpenCVE Enrichment