Impact
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 contain a flaw in the Security Framework that permits an unauthenticated attacker with HTTP network access to compromise the portal. The vulnerability can be leveraged to take full control of the application, resulting in complete loss of confidentiality, integrity, and availability. The CVSS 3.1 score of 10.0 reflects the severity of this remote code execution possibility.
Affected Systems
The vulnerability impacts Oracle WebCenter Portal product of Oracle Fusion Middleware. Affected releases are version 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The flaw is easily exploitable, requiring only basic network connectivity via HTTP and no authentication. The EPSS score is below 1%, indicating a currently low exploitation probability, and the vulnerability is not listed in CISA KEV. Nevertheless, the high CVSS score and the ability to take over the portal mean that any environment running these versions is at significant risk of compromise, including potential impacts on other dependent Oracle products.
OpenCVE Enrichment