Impact
An easily exploitable flaw in Oracle WebCenter Portal, specifically within the Runtime Tools component, lets a low‑privileged threat actor with network access over HTTPS compromise the portal. Successful exploitation can result in full takeover, affecting confidentiality, integrity and availability of the application. The vulnerability is counted as a scope‑changing vector, meaning it can elevate the attacker’s privileges beyond their original level.
Affected Systems
Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These are part of Oracle Fusion Middleware and are delivered by Oracle Corporation.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 indicates critical severity. With an EPSS score of less than 1 % the likelihood of exploitation is currently low, and the vulnerability is not listed in CISA’s KEV catalog. However, the impact is high: an attacker can achieve remote code execution and gain control of the portal. Attackers would need only network connectivity to the HTTPS endpoints and can launch the exploit with minimal privileges. System administrators should assess their exposure and apply remediation promptly.
OpenCVE Enrichment