Impact
The vulnerability exists in the Security Framework component of Oracle WebCenter Portal, enabling a low‑privileged attacker with network access over HTTPS to compromise the target system. This flaw can lead to full takeover of the portal, exposing sensitive data and allowing modification or destruction of content. The flaw impacts confidentiality, integrity, and availability, and may extend beyond the portal to other Fusion Middleware products, as the description notes a scope change.
Affected Systems
Affected versions are Oracle WebCenter Portal 12.2.1.4.0 and 14.1.2.0.0. These releases were identified under the CNA vendor Oracle Corporation for Oracle WebCenter Portal.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 indicates critical severity, with low attack complexity and low required privileges but a change in scope. The EPSS score of less than 1% suggests low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description stating network access via HTTPS, the likely attack vector is an initial connection to the portal over HTTPS, after which the attacker can exploit the unsecured Security Framework to gain control. No user interaction or special conditions are required, making this vulnerability highly exploitable for an attacker who can reach the portal.
OpenCVE Enrichment