Impact
A critical vulnerability exists in the Security Framework component of Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0. A low‑privileged attacker with network access over HTTPS can exploit the flaw to fully compromise the portal. The impact includes full confidentiality, integrity, and availability loss, effectively granting the attacker control of the entire application. The CVSS vector indicates that the vulnerability is remotely reachable, requires low authentication, and results in a scope change allowing privilege escalation.
Affected Systems
The affected products are Oracle WebCenter Portal from Oracle Corporation, specifically the 12.2.1.4.0 and 14.1.2.0.0 releases. Any instance of these versions deployed in an environment is susceptible unless mitigated.
Risk and Exploitability
The CVSS base score of 9.9 marks this flaw as critical, and the EPSS score of less than 1% indicates a low but nonzero current exploitation probability. Because the attack vector is over HTTPS, network‑level exposure is required; a user with minimal privileges can trigger the exploit. While the flaw is not listed in the CISA KEV catalog, its severity and potential to extend impact to other products make it a high priority for remediation.
OpenCVE Enrichment