Impact
The vulnerability resides in the Security Framework of Oracle WebCenter Portal and allows a low‑privileged attacker with network access over HTTP to compromise the application. The flaw can be exploited easily and leads to full takeover of the portal, affecting confidentiality, integrity, and availability. The CVSS 3.1 base score of 9.9 reflects a high‑severity risk with abundant impact across all security categories.
Affected Systems
Affected are Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, delivered by Oracle Corporation as part of its Fusion Middleware suite.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, while the EPSS score of less than 1 % suggests that exploitation is not common yet; however, the low privilege requirement and availability of network‑based HTTP access make the attack surface broad. The vulnerability is not listed in CISA's KEV catalog, so no evidence of widespread exploitation exists at present, yet the potential for scope change means other products could be affected if the portal is compromised. Attackers would likely use the exposed HTTP endpoint to push malicious code or execute privileged actions, taking over the portal and possibly other connected systems.
OpenCVE Enrichment