Impact
Oracle WebCenter Content 14.1.2.0.0 contains an easily exploitable flaw that lets an attacker reach the application over HTTP without authentication, but the attacker still needs a separate human interaction to trigger the vulnerability. Once exploited, the attacker can create, delete, or change critical data, potentially gaining full control over all data accessible through the Content Server. The vulnerability compromises confidentiality and integrity but not availability.
Affected Systems
The affected products are Oracle WebCenter Content 14.1.2.0.0 from Oracle Corporation cited in the Oracle Fusion Middleware family. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS 3.1 score of 9.3 highlights a high‑severity issue with high impact on confidentiality and integrity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. Extrapolated from the description, the likely attack path involves an unauthenticated HTTP request combined with user interaction to trigger the flaw, leading to unauthorized data operations and a scope change to include additional Oracle products.
OpenCVE Enrichment